Compare commits

...
15 Commits
Author SHA1 Message Date
KimiSwitch Dev 5138a295e0 chore(release): bump to v0.7.12 — 适配 kimi-code 0.40.1(flag 清单/优先级/危险命令守卫)+ WebUI 竞态修复 + models-dev 7495/212
Release / Version consistency (push) Canceled after 0s
Release / Build (macos-latest) (push) Canceled after 0s
Release / Build (ubuntu-latest) (push) Canceled after 0s
Release / Build (windows-latest) (push) Canceled after 0s
Release / Attach macOS install script (push) Canceled after 0s
2026-09-03 10:12:17 +08:00
KimiSwitch Dev a02179c9da chore(data): 同步 models-dev 最新快照(7495 模型 / 212 供应商) 2026-09-03 10:11:10 +08:00
KimiSwitch Dev 86a128efea feat: 适配 kimi-code 0.40.1 —— flag 清单/优先级语义/危险命令守卫
- flag 清单 9→10:新增 file_history、search_worker;secondary-model
  0.40.1 起默认开启(defaultEnabled)
- env 探测补齐为 12 项元组(10 flag + master + legacy),修正此前
  tower/subagent_fork/wait_for/auto_session_title 四项漏探
- 优先级语义跟随上游 flagService:单 flag env > [experimental] 显式值
  > master env(仅强制开)> 默认。master env 不再锁定 UI;setExperimentalFlag
  增加 explicitFalse 路径,关闭默认开/master 强开的 flag 时写字面 false
- 权限设置新增 dangerous_command_guard 开关(默认开,写 [permission]
  蛇形键;env KIMI_CODE_DANGEROUS_COMMAND_GUARD 运行时覆盖 config)
- 新增 11 个测试(注册表/写语义/守卫读写)
2026-09-03 10:10:52 +08:00
KimiSwitch Dev 6a7c8f5393 fix(webui): 修复首次打开慢时多次点击导致的竞态报错
open_kimi_web_embedded 加 launch_lock 串行化并发调用,拿锁后重查单例;
oneshot 在锁内等待主线程建窗完成,封死命令返回后的残留空档。
spawned_by_me 门控失败路径的 server 清理,复用的 server 不再被误杀;
spawn 前用 try_wait 检查已有子进程避免覆盖泄漏。前端两个打开按钮加
busy 态防重入(打开中...)。
2026-09-03 10:10:40 +08:00
KimiSwitch Dev 8b597496b3 chore(release): bump to v0.7.11 — 适配 kimi-code 0.39.1(thinking keep/loop_control/flags)+ 归档元数据化 + 子代理池修复 + models-dev 7482/207
Release / Version consistency (push) Canceled after 0s
Release / Build (macos-latest) (push) Canceled after 0s
Release / Build (ubuntu-latest) (push) Canceled after 0s
Release / Build (windows-latest) (push) Canceled after 0s
Release / Attach macOS install script (push) Canceled after 0s
2026-08-29 11:15:40 +08:00
KimiSwitch Dev 8ce3f290ed chore(data): 同步 models-dev 最新快照(7482 模型 / 207 供应商) 2026-08-29 11:14:11 +08:00
KimiSwitch Dev 8639188968 fix(sessions): 归档迁移为 state.json 元数据(archived/archivedAt,与上游 v2 setArchived 逐字段一致),不再物理搬目录;遗留 .kcd-archive 目录兼容识别与恢复;归档不再动 session_index 2026-08-29 11:14:01 +08:00
KimiSwitch Dev 45ec073e6f fix(config): 适配 kimi-code 0.39.1——thinking keep 写字符串 off(布尔会整节作废)、存量布尔归一化;loop_control 默认只写 v2 键(legacy flag 才双写);effort 移除 max 档;实验 flags 补 remote-control、wait_for/minidb 标默认开启 2026-08-29 11:13:58 +08:00
KimiSwitch Dev 7435198fcc chore(release): bump to v0.7.10 — 配置写回保护(导入基线 + 未知供应商类型原样保留)
Release / Version consistency (push) Canceled after 0s
Release / Attach macOS install script (push) Canceled after 0s
Release / Build (macos-latest) (push) Canceled after 0s
Release / Build (ubuntu-latest) (push) Canceled after 0s
Release / Build (windows-latest) (push) Canceled after 0s
2026-08-29 00:10:52 +08:00
KimiSwitch Dev 67db19eda4 fix(config): 保存不再误删 CLI 后加的顶层配置节 + 未知供应商类型原样保留
- 导出 stale-key 清理增加导入基线(imported_section_keys):CLI 在导入后
  新增的顶层节(kimi-code 0.38+ 的 [task]/[swarm]/[cron] 等)在保存时
  原样保留;用户在 UI 显式删除的节仍被移除;空基线(SQLite 快照恢复)
  不删任何键(安全退化)
- ProviderType 增加 Unknown(String) 变体,手写 serde 保持纯字符串线格式,
  上游新增的 type 值往返不再被改写为 kimi;SQLite 快照恢复路径同步修复;
  模型发现对未知类型返回明确错误,不再误用 KIMI_API_KEY
- 新增 3 个往返测试(106 个 Rust 测试全绿),前端 tsc/vitest 通过
2026-08-29 00:09:55 +08:00
KimiSwitch Dev 9764929919 chore(release): bump to v0.7.9 — models.dev 数据同步(GLM-5.3/5.3-Flash、Qwen3.8、豆包 Seed 2.x)
Release / Version consistency (push) Canceled after 0s
Release / Build (macos-latest) (push) Canceled after 0s
Release / Build (ubuntu-latest) (push) Canceled after 0s
Release / Build (windows-latest) (push) Canceled after 0s
Release / Attach macOS install script (push) Canceled after 0s
2026-08-27 09:42:14 +08:00
KimiSwitch Dev f40e4be577 chore(data): 同步 models-dev 2026-08-27 快照(7343 模型 / 203 供应商)— 新增 GLM-5.3/5.3-Flash、Qwen3.8、豆包 Seed 2.x 等 74 模型,58 处价格与 56 处能力更新;补齐 public/ 静态资源(原停留在 08-01) 2026-08-27 09:37:26 +08:00
KimiSwitch Dev 138a2b8547 chore(data): 同步 models-dev 最新模型数据(7284 模型 / 199 供应商) 2026-08-25 13:12:11 +08:00
KimiSwitch Dev 769852c4b5 feat(flags): v0.7.8 — 实验开关同步 kimi-code 上游 7 旗标(tower/subagent_fork/wait_for/auto_session_title 新增,acp-v2 移除)+ 修复模型用量上下显示不同步(状态提升至卡片层)
Release / Version consistency (push) Canceled after 0s
Release / Build (macos-latest) (push) Canceled after 0s
Release / Build (ubuntu-latest) (push) Canceled after 0s
Release / Build (windows-latest) (push) Canceled after 0s
Release / Attach macOS install script (push) Canceled after 0s
2026-08-25 11:20:34 +08:00
KimiSwitch Dev 8221e05db1 feat(oauth): v0.7.7 — 双区域 OAuth 支持(适配 kimi-code 0.38.0 global 账号)+ 修复模型占位别名跟随 + models.dev 快照刷新
Release / Version consistency (push) Canceled after 0s
Release / Build (macos-latest) (push) Canceled after 0s
Release / Build (ubuntu-latest) (push) Canceled after 0s
Release / Build (windows-latest) (push) Canceled after 0s
Release / Attach macOS install script (push) Canceled after 0s
2026-08-22 14:00:20 +08:00
39 changed files with 113745 additions and 68001 deletions

No files matched your search

+5 -5
View File
@@ -81,11 +81,11 @@ jobs:
### 本次更新
- **高级设置**:原「子代理设置」升级为「高级设置」,聚合子代理模型指定、实验功能开关与 WebUI 快捷入口
- **仪表盘热力图双击弹窗**:双击热力图方块即可查看当日模型用量分布,每种模型展示 Token / 请求次数 / 费用 / 命中率
- **子代理模型指定(实验功能)**:为子代理绑定次主力模型,不再默认继承主模型;实验开关改为滑动开关并修复开启态隐形
- **兼容 kimi-code 0.33+(v2 引擎)**:`loop_control` 写入新键名 `max_attempts_per_step`,旧配置自动迁移并保留旧键兼容 `KIMI_CODE_LEGACY_FLAG=1`;hooks 候选补充新事件
- models.dev 模型数据同步;官网企业版视觉升级;出品公司标识统一
- **模型数据同步(models.dev 2026-08-27)**:7343 个模型 / 203 个供应商
- **新增 GLM-5.3 / GLM-5.3-Flash 全线接入**:智谱官方、OpenRouter、Cloudflare、DeepInfra、HuggingFace、火山引擎等约 20 条渠道;GLM-5.3-Flash 定价 $0.075 / $0.25(输入/输出,每百万 token)
- 新增 coding plan 渠道:`zhipuai-coding-plan/glm-5.3`、`glm-5.3-highspeed`、`glm-5.3-flash`
- 新增 Qwen3.8 系列、火山引擎豆包 Seed 2.x 全系、DeepSeek-V4 GA 版、MiniMax-M2.7/M3 等共 74 个模型条目
- 价格更新 58 处、能力信息修正 56 处(详见 release-notes-v0.7.9.md)
### Downloads by platform
+8 -2
View File
@@ -123,7 +123,7 @@
![会话管理](docs/screenshots/sessions.png)
按工作区隔离浏览 Kimi Code 会话,支持活跃/已归档/全部筛选;流式逐行预览(20MB 字节上限,500 字符折叠);归档/取消归档/批量删除。
按工作区隔离浏览 Kimi Code 会话,支持活跃/已归档/全部筛选;流式逐行预览(20MB 字节上限,500 字符折叠);归档/取消归档/批量删除。归档写入 `state.json` 元数据(与 CLI v2 一致),旧版本物理归档目录 `.kcd-archive/` 仍可识别与恢复。
## 架构总览
@@ -239,7 +239,7 @@
- 按工作区隔离浏览 Kimi Code 会话,支持活跃/已归档/全部筛选
- 流式逐行预览(20MB 字节上限,500 字符折叠可展开)
- 归档 / 取消归档 / 批量删除
- 归档 / 取消归档 / 批量删除(归档写入 `state.json` 元数据,与 CLI v2 一致;旧版本物理归档目录 `.kcd-archive/` 仍可识别与恢复)
- 早期版本的"闪崩"已通过流式读取 + 限制解决
### 设置面板
@@ -543,6 +543,12 @@ A: 需要分两步:
**Q: 切换会覆盖其他供应商吗?**
A: 不会。Kimi Code 的 `config.toml` 始终写入全部供应商,仅 `default_model` 决定生效项。这与 CLI 原生 `/provider` 行为一致。
**Q: 在 Kimi Code CLI 里新增的顶层配置节(如 `[task]`/`[swarm]`)会被保存时删掉吗?**
A: 不会(v0.7.10 起)。保存时以加载配置那一刻的顶层键为基线,CLI 后加的节原样保留;只有在本应用中显式删除的节才会从 `config.toml` 移除。
**Q: 遇到 Kimi Code 新增的供应商类型(`type` 值)会怎样?**
A: 原样保留,不再改写为 `kimi`。编辑界面会显示原始类型值(标注"未知类型");该供应商不支持的操作(如模型发现)会返回明确错误提示。
**Q: 新增/激活的供应商位置怎么变?**
A: 自动提升到列表最前,UI 立即反映。
+1 -1
View File
@@ -1,7 +1,7 @@
{
"name": "kimiswitch",
"private": true,
"version": "0.7.6",
"version": "0.7.12",
"type": "module",
"scripts": {
"dev": "vite",
+77684 -58645
View File
File diff suppressed because it is too large. Load diff
+8
View File
@@ -0,0 +1,8 @@
## v0.7.10
### 配置写回保护(适配 kimi-code 0.38+ 配置演进)
- **修复:保存不再误删 CLI 新增的顶层配置节**。此前在 Kimi Switch 加载配置后,若 Kimi Code CLI 往 `config.toml` 写入了新的顶层节(如 0.38+ 的 `[task]` / `[swarm]` / `[cron]` / `[tools]` / `[identity]` / `[token_counting]` 等),回到 Kimi Switch 保存时会把这些节**静默删除**。现在以导入时的顶层键为基线:CLI 后加的节原样保留;在界面中显式删除的节仍会被移除;老数据(无基线,如 SQLite 快照恢复)不删任何键
- **修复:未知供应商类型不再被改写**。`config.toml` 中 Kimi Code 新增的供应商 `type` 值往返读写后不再被改写成 `kimi`,原样保留;编辑器 API 格式下拉框显示原始值(标注"未知类型");模型发现等不支持的操作返回明确错误提示,不再误用 `KIMI_API_KEY`
- SQLite 快照恢复路径同步修复(此前从快照恢复同样会丢失未知类型)
- 新增 3 个配置往返回归测试(Rust 测试 106 项全绿,前端 tsc / vitest 通过)
+22
View File
@@ -0,0 +1,22 @@
## v0.7.11
### 适配 kimi-code 0.39.1
- **修复:`[thinking]` 保留开关不再破坏思考配置**。此前在 UI 关闭"保留思考内容"会写入布尔 `keep = false`,而上游两个引擎都只接受字符串——v2 会把整个 `[thinking]` 节校验失败并丢弃。现改为写 `keep = "off"`,存量配置里的布尔值加载时自动归一化
- **修复:`loop_control` 不再触发上游废弃告警**。默认只写新键 `max_attempts_per_step` 并清理存量旧键 `max_retries_per_step`;仅检测到 `KIMI_CODE_LEGACY_FLAG`(v1 引擎)时才双写
- **思考强度移除 `max` 档**(上游已自动迁移为 `high`),存量配置显示归一
- **实验开关同步上游全集**:新增 remote-control;`wait_for` 与 persistence_minidb_readmodel 已在上游转正默认开启,UI 会标注"默认开启"(显式关闭优先)
### 会话归档与上游 v2 对齐
- **归档不再搬动文件**:改为在会话 `state.json` 写入 `archived`/`archivedAt` 元数据(与 CLI v2 的 `setArchived` 逐字段一致),CLI 侧与 Kimi Switch 侧归档状态从此互通
- 旧版本物理归档的会话(`.kcd-archive/` 目录)仍可识别为已归档并正常恢复
- 归档不再改写 `session_index.jsonl`(删除会话的行为不变)
### 子代理模型池修复
- **修复:模型池无法添加第二个条目**。从"仅默认模型"的隐式单条目形态添加条目时,默认模型现在会自动物化进池,不再被"默认模型不在模型池中"的校验拦截
### 模型数据同步
- models.dev 快照刷新至 **7482 个模型 / 207 个供应商**
+16
View File
@@ -0,0 +1,16 @@
# KimiSwitch v0.7.12
## 适配 kimi-code 0.40.1
- **实验 flag 清单更新(9→10)**:新增 `file_history`(轮级文件历史快照)、`search_worker`(kap-server 全局搜索 worker);`secondary-model`(子代理次主力模型)自 kimi-code 0.40.1 起默认开启,设置页显示"默认开启"徽章
- **flag 优先级语义修正**:跟随上游新优先级——单 flag 环境变量 > `[experimental]` 显式配置 > 总开关环境变量(仅强制开)> 默认值。总开关 `KIMI_CODE_EXPERIMENTAL_FLAG` 不再锁定全部开关,显式写入的 false/true 优先生效
- **环境变量探测补齐**:`tower` / `subagent_fork` / `wait_for` / `auto_session_title` 等此前漏探测的环境变量现在会正确显示"被环境变量锁定"状态
- **新增危险命令守卫开关**:权限设置页可配置 `[permission] dangerous_command_guard`(默认开启)——Auto 模式直接拒绝 `rm -rf` / `shutdown` 等危险命令,其它模式强制询问,关闭后回归旧行为
## 修复
- **WebUI 打开竞态**:首次打开较慢时多次点击"在应用内打开"不再报错——并发调用串行化 + 后到的点击自动聚焦已有窗口;失败路径不再误杀正在使用的 server;前端按钮增加"打开中..."防重入态
## 数据
- models-dev 快照更新至 7495 模型 / 212 供应商
+18
View File
@@ -0,0 +1,18 @@
## v0.7.7
### 双区域 OAuth 支持(适配 kimi-code 0.38.0)
- 适配官方 CLI v0.38.0 引入的双区域登录(mainland-cn `auth.kimi.com` / global `auth.kimi.ai`,#2862)
- **凭据动态解析**:按 provider 的 oauth ref(`key` / `oauthHost`)推导凭据文件与 token 刷新端点,global 账号(`credentials/kimi-code-env-<sha256>.json`)可正常查询用量;无 oauth ref 的老配置完全走旧路径,零回归
- **用量查询区域适配**:`api.kimi.ai/coding` 识别为官方套餐,usages 查询按 provider base_url 拼接
- **内置登录区域选择**:应用内 Kimi 登录对话框新增「中国大陆 / 国际版 (kimi.ai)」选择,登录成功后同步落盘凭据 + 按官方 CLI 行为 provision `[providers."managed:kimi-code"]`(global 写 `oauthHost`,cn 不写,保持区域信号正确)
- scoped key 推导与官方 CLI 逐字节一致(`JSON.stringify({oauthHost, baseUrl})` 的 sha256 前 16 位 hex),hash 值经独立复算验证
### 修复
- 修复手动添加模型后模型用量显示为 `xxx/新模型` 而非真实模型名:填入实际模型 ID 时别名自动跟随为 `<provider>/<model-id>`(含输入中间态跟随),连续添加占位条目不再互相覆盖
- 修复 managed(OAuth)供应商自填 `api_key` 在保存配置时被清空的问题:无 key 时按官方 provisioned 形态写空行,用户自填 key 完整保留
### 模型数据更新
- models.dev 快照刷新(**7246 模型 / 193 供应商**):新增 **DeepSeek V4 Flash Vision Exp**(官方定价与 v4-flash 一致)、**Ox Alpha Free**(opencode-go,免费)等
+13
View File
@@ -0,0 +1,13 @@
## v0.7.8
### 修复:模型用量上下显示不同步
- 修复同一供应商卡片上,上方用量摘要(含 🔄 刷新按钮)刷新后、下方用量进度条仍停留在旧数据的问题(如上方 24% vs 下方 8%)
- 用量查询状态提升至卡片层统一持有:点刷新、自动轮询后,两处显示同帧同步更新
- 自动刷新间隔不再只挂在其中一处显示上,每卡片恰好一份定时器,行为不变
### 实验功能开关同步 kimi-code 最新旗标注册表
- 高级设置的实验功能清单对齐 kimi-code 上游 v2 旗标注册表(7 项)
- 新增开关:**Tower 模式**(多智能体协同,/tower 命令切换)、**子代理 Fork 上下文**(Agent/AgentSwarm 携带主代理会话快照)、**WaitFor 工具**(回合内等待后台任务)、**自动会话标题**(托管 chat_title 工具)
- 移除上游已废弃的 **ACP v2 协议** 开关(手写进 config.toml 的配置仍会完整保留)
+10
View File
@@ -0,0 +1,10 @@
## v0.7.9
### 模型数据同步(models.dev 2026-08-27 快照)
- 模型库刷新至 **7343 个模型 / 203 个供应商**,内置快照与官网静态资源同步更新
- **新增 GLM-5.3 / GLM-5.3-Flash 全线接入**:智谱官方、OpenRouter、Cloudflare Workers AI、DeepInfra、HuggingFace、火山引擎等约 20 条渠道,GLM-5.3-Flash 定价 $0.075/$0.25(输入/输出,每百万 token)
- 新增 coding plan 渠道:`zhipuai-coding-plan/glm-5.3`、`glm-5.3-highspeed`、`glm-5.3-flash`
- 新增 Qwen3.8 系列(27B / Flash / 2.4T-A95B)、火山引擎豆包 Seed 2.x 全系(2-0 Pro/Lite/Mini/Code-Preview、2-1 Pro/Turbo)、DeepSeek-V4 GA 版、MiniMax-M2.7/M3 等共 74 个模型条目
- 价格更新 58 处:Amazon Bedrock GPT-5.6 Sol 降价(5.5→4)、DeepSeek V4 Flash 0731 半价、Kimi-Latest 微调降价等
- 能力信息修正 56 处:MiniMax-M2/M3 上下文扩展至 200K/1M、Grok 4.x 补充 structured_output、豆包 Seed 补充图像输入等
+2 -1
View File
@@ -1978,7 +1978,7 @@ dependencies = [
[[package]]
name = "kimiswitch"
version = "0.7.6"
version = "0.7.12"
dependencies = [
"anyhow",
"chrono",
@@ -1991,6 +1991,7 @@ dependencies = [
"rusqlite",
"serde",
"serde_json",
"sha2",
"tauri",
"tauri-build",
"tauri-plugin-opener",
+4 -1
View File
@@ -1,6 +1,6 @@
[package]
name = "kimiswitch"
version = "0.7.6"
version = "0.7.12"
description = "Kimi Switch - model config manager"
authors = ["codingplan.site"]
edition = "2021"
@@ -29,6 +29,9 @@ tokio = { version = "1", features = ["sync", "fs", "io-util"] }
# Plugin marketplace: zip extraction (deflate-only; no extra compression
# backends needed for plugin archives).
zip = { version = "2", default-features = false, features = ["deflate"] }
# Scoped OAuth credential keys (oauth/kimi-code-env-<sha256>) for non-mainland
# regions, mirroring the official CLI's resolveKimiCodeOAuthKey.
sha2 = "0.10"
[dev-dependencies]
tempfile = "3"
+162 -76
View File
@@ -244,6 +244,7 @@ fn build_active_config(config: &Config) -> Config {
providers,
models,
raw_other: config.raw_other.clone(),
imported_section_keys: config.imported_section_keys.clone(),
}
}
@@ -277,6 +278,9 @@ pub async fn list_provider_models(provider: Provider) -> Result<Vec<DiscoveredMo
ProviderType::Anthropic => fetch_anthropic_models(&base, &api_key).await,
ProviderType::GoogleGenai => fetch_google_genai_models(&base, &api_key).await,
ProviderType::Vertexai => Err("Vertex AI model discovery requires GCP project/location configuration and is not yet supported".to_string()),
ProviderType::Unknown(s) => Err(format!(
"unsupported provider type for model discovery: {s}"
)),
}
}
@@ -338,8 +342,12 @@ fn resolve_api_key(provider: &Provider) -> Option<String> {
return Some(key.clone());
}
}
let env_key = expected_api_key_key(&provider.provider_type);
provider.env.get(env_key).filter(|s| !s.is_empty()).cloned()
if let Some(env_key) = expected_api_key_key(&provider.provider_type) {
if let Some(key) = provider.env.get(env_key).filter(|s| !s.is_empty()) {
return Some(key.clone());
}
}
None
}
fn resolve_base_url(provider: &Provider) -> String {
@@ -356,13 +364,16 @@ fn resolve_base_url(provider: &Provider) -> String {
})
}
fn expected_api_key_key(provider_type: &ProviderType) -> &'static str {
/// Well-known env var fallback for the API key per provider type; `None`
/// for unknown types (no well-known variable name to look up).
fn expected_api_key_key(provider_type: &ProviderType) -> Option<&'static str> {
match provider_type {
ProviderType::Kimi => "KIMI_API_KEY",
ProviderType::Anthropic => "ANTHROPIC_API_KEY",
ProviderType::Openai | ProviderType::OpenaiResponses => "OPENAI_API_KEY",
ProviderType::GoogleGenai => "GOOGLE_API_KEY",
ProviderType::Vertexai => "VERTEXAI_API_KEY",
ProviderType::Kimi => Some("KIMI_API_KEY"),
ProviderType::Anthropic => Some("ANTHROPIC_API_KEY"),
ProviderType::Openai | ProviderType::OpenaiResponses => Some("OPENAI_API_KEY"),
ProviderType::GoogleGenai => Some("GOOGLE_API_KEY"),
ProviderType::Vertexai => Some("VERTEXAI_API_KEY"),
ProviderType::Unknown(_) => None,
}
}
@@ -650,15 +661,19 @@ pub async fn query_provider_usage(
.clone()
.filter(|s| !s.trim().is_empty())
.or_else(|| {
provider
.env
.get(expected_api_key_key(&provider.provider_type))
expected_api_key_key(&provider.provider_type)
.and_then(|env_key| provider.env.get(env_key))
.cloned()
.filter(|s| !s.is_empty())
});
let mut oauth_err: Option<String> = None;
if api_key.is_none() && provider.managed {
match crate::oauth::get_valid_access_token().await {
// Resolve the credential slot + refresh host from the provider's oauth
// ref (region-aware); with no ref this falls back to the mainland
// default, preserving pre-region behavior.
let oauth_ref = crate::oauth::oauth_ref_from_provider(provider);
let oauth_base_url = provider.base_url.as_deref().unwrap_or("");
match crate::oauth::get_valid_access_token(oauth_ref.as_ref(), oauth_base_url).await {
Ok(token) => api_key = Some(token),
Err(e) => oauth_err = Some(e),
}
@@ -999,6 +1014,9 @@ pub struct KimiWebState {
window: Mutex<Option<tauri::WebviewWindow>>,
/// The `kimi web` child spawned by this app (None when reusing a server).
child: Mutex<Option<std::process::Child>>,
/// Serializes `open_kimi_web_embedded` invocations: a rapid double-click
/// queues here instead of racing the window/server setup.
launch_lock: tokio::sync::Mutex<()>,
}
const KIMI_WEB_PORT: u16 = 58627;
@@ -1049,7 +1067,13 @@ pub async fn open_kimi_web_embedded(
app: tauri::AppHandle,
state: tauri::State<'_, KimiWebState>,
) -> Result<(), String> {
// Singleton: focus the existing window instead of creating a second one.
// Serialize concurrent invocations (rapid double-click): a second call
// waits here until the first has finished building the window, then
// re-checks the singleton below and focuses it instead.
let _guard = state.launch_lock.lock().await;
// Singleton (re-checked after acquiring the lock): focus the existing
// window instead of creating a second one.
if let Ok(guard) = state.window.lock() {
if let Some(w) = guard.as_ref() {
if w.is_visible().unwrap_or(false) {
@@ -1060,8 +1084,21 @@ pub async fn open_kimi_web_embedded(
}
}
// Reuse an already-running server, otherwise spawn `kimi web --no-open`.
if !kimi_web_alive(Duration::from_millis(800)).await {
// Reuse the server this app spawned earlier (still running), or a server
// already running outside the app; only spawn when neither is present.
// `spawned_by_me` gates every failure-path kill, so a reused server is
// never terminated.
let mut spawned_by_me = false;
let mut child_running = false;
if let Ok(mut guard) = state.child.lock() {
// try_wait: Ok(None) = still running. Exited or unwaitable children
// are treated as gone so a fresh server is spawned below.
child_running = guard
.as_mut()
.map(|child| child.try_wait().map(|st| st.is_none()).unwrap_or(false))
.unwrap_or(false);
}
if !child_running && !kimi_web_alive(Duration::from_millis(800)).await {
let mut cmd = std::process::Command::new("kimi");
cmd.args(["web", "--no-open", "--port", &KIMI_WEB_PORT.to_string()]);
#[cfg(windows)]
@@ -1076,6 +1113,7 @@ pub async fn open_kimi_web_embedded(
format!("failed to start `kimi web`: {e}")
}
})?;
spawned_by_me = true;
if let Ok(mut guard) = state.child.lock() {
*guard = Some(child);
}
@@ -1083,57 +1121,79 @@ pub async fn open_kimi_web_embedded(
// Wait for the server to come up (fresh start takes a moment).
if !kimi_web_alive(Duration::from_secs(8)).await {
kill_spawned_kimi_web(&state);
if spawned_by_me {
kill_spawned_kimi_web(&state);
}
return Err(format!("kimi web did not come up within 8s ({KIMI_WEB_ORIGIN})"));
}
// Create the window on the main thread (required on macOS).
// Build the URL, then create the window on the main thread (required on
// macOS). The build result is awaited while still holding `launch_lock`,
// so a concurrent second invocation blocks here and then lands on the
// singleton re-check above once the window exists.
let url: tauri::Url = match kimi_web_url().parse() {
Ok(u) => u,
Err(_) => return Err("invalid kimi web url".to_string()),
};
let app = app.clone();
tauri::async_runtime::spawn(async move {
let builder_app = app.clone();
let _ = app.run_on_main_thread(move || {
match tauri::WebviewWindowBuilder::new(
&builder_app,
KIMI_WEB_WINDOW_LABEL,
tauri::WebviewUrl::External(url),
)
.title("Kimi Code WebUI")
.inner_size(1100.0, 750.0)
.resizable(true)
.center()
.build()
{
Ok(window) => {
// Track the window for the singleton check.
if let Ok(mut guard) = builder_app.state::<KimiWebState>().window.lock() {
*guard = Some(window.clone());
}
// Clean up when the window closes: forget it and stop the
// `kimi web` server we spawned (reused servers are untouched).
let w = window.clone();
window.on_window_event(move |event| match event {
tauri::WindowEvent::Destroyed => {
let app = w.app_handle().clone();
let state = app.state::<KimiWebState>();
if let Ok(mut guard) = state.window.lock() {
*guard = None;
}
kill_spawned_kimi_web(&state);
}
_ => {}
});
}
Err(_) => {
// Window creation failed (e.g. rapid double-click racing
// the singleton check): don't leak the server we spawned.
kill_spawned_kimi_web(&builder_app.state::<KimiWebState>());
let (tx, rx) = tokio::sync::oneshot::channel::<Result<(), String>>();
let builder_app = app.clone();
app.run_on_main_thread(move || {
let result = build_kimi_web_window(&builder_app, &url);
let _ = tx.send(result);
})
.map_err(|e| format!("failed to queue window creation: {e}"))?;
match rx.await {
Ok(result) => {
if let Err(e) = result {
// Window creation failed (e.g. label already taken): only stop
// the server when this invocation spawned it.
if spawned_by_me {
kill_spawned_kimi_web(&state);
}
return Err(e);
}
});
Ok(())
}
// Sender dropped without a result (app shutting down, build never
// ran): never kill the server — a later invocation may reuse it.
Err(_) => Ok(()),
}
}
/// Build the embedded WebUI window on the main thread and track it for the
/// singleton check. On success, wires close/destroy events to forget the
/// window and stop the `kimi web` server this app spawned (reused servers are
/// untouched).
fn build_kimi_web_window(app: &tauri::AppHandle, url: &tauri::Url) -> Result<(), String> {
let window = tauri::WebviewWindowBuilder::new(
app,
KIMI_WEB_WINDOW_LABEL,
tauri::WebviewUrl::External(url.clone()),
)
.title("Kimi Code WebUI")
.inner_size(1100.0, 750.0)
.resizable(true)
.center()
.build()
.map_err(|e| format!("failed to create kimi web window: {e}"))?;
// Track the window for the singleton check.
if let Ok(mut guard) = app.state::<KimiWebState>().window.lock() {
*guard = Some(window.clone());
}
// Clean up when the window closes: forget it and stop the `kimi web`
// server we spawned (reused servers are untouched).
let w = window.clone();
window.on_window_event(move |event| match event {
tauri::WindowEvent::Destroyed => {
let app = w.app_handle().clone();
let state = app.state::<KimiWebState>();
if let Ok(mut guard) = state.window.lock() {
*guard = None;
}
kill_spawned_kimi_web(&state);
}
_ => {}
});
Ok(())
}
@@ -1249,46 +1309,72 @@ pub fn open_external_url(app: tauri::AppHandle, url: String) -> Result<(), Strin
// Kimi OAuth device-code sign-in (in-app replacement for `kimi login`)
// ---------------------------------------------------------------------------
/// Step 1: ask auth.kimi.com for a user_code + verification URI.
/// Step 1: ask the region's OAuth host for a user_code + verification URI.
/// `region` is `"cn"` (default) or `"global"`.
#[tauri::command]
pub async fn kimi_oauth_start() -> Result<crate::oauth::DeviceAuthorization, String> {
crate::oauth::start_device_authorization().await
pub async fn kimi_oauth_start(
region: Option<String>,
) -> Result<crate::oauth::DeviceAuthorization, String> {
let region = crate::oauth::KimiRegion::from_opt(region.as_deref());
crate::oauth::start_device_authorization(region).await
}
/// Step 2: poll the token endpoint until the user approves. On success the
/// tokens are written to the CLI credentials file (`kimi login` no longer
/// needed). Errors are transient (network); deterministic outcomes
/// (pending / success / expired / denied / timeout) come back in the enum.
/// Step 2: poll the region's token endpoint until the user approves. On
/// success the tokens are written to the region's credentials file and the
/// provider is provisioned in config.toml (`kimi login` no longer needed).
/// Errors are transient (network); deterministic outcomes (pending / success /
/// expired / denied / timeout) come back in the enum.
#[tauri::command]
pub async fn kimi_oauth_poll(
device_code: String,
interval: i64,
region: Option<String>,
) -> Result<crate::oauth::DevicePollStatus, String> {
crate::oauth::poll_device_token(&device_code, interval).await
let region = crate::oauth::KimiRegion::from_opt(region.as_deref());
crate::oauth::poll_device_token(&device_code, interval, region).await
}
// ---------------------------------------------------------------------------
// Experimental feature env-var probe (Kimi Code secondary model etc.)
// ---------------------------------------------------------------------------
/// Read the Kimi Code experimental-feature environment variables that are
/// currently set (non-empty) in this process's environment. The frontend
/// uses the result to mark config.toml `[experimental]` toggles as locked:
/// env vars outrank the config file in Kimi Code's flag resolution.
/// Read the Kimi Code environment variables that are currently set (non-empty)
/// in this process's environment. Every `[experimental]` feature env var is
/// probed — the frontend uses a per-feature env var to mark the matching
/// config.toml `[experimental]` toggle as locked, since a single-feature env
/// var outranks the config file in Kimi Code's flag resolution. The master
/// `KIMI_CODE_EXPERIMENTAL_FLAG` (0.40.1+: only force-ONs flags without an
/// explicit config entry; never locks a toggle) and `KIMI_CODE_LEGACY_FLAG`
/// are probed too — the latter lets AgentSettingsPanel decide whether to
/// dual-write the v1 engine's loop_control keys.
///
/// The flag id → env var mapping mirrors `EXPERIMENTAL_FLAGS` in
/// src/lib/subagent-settings.ts; keep both lists in sync.
///
/// Truthy values per the CLI: `1` / `true` / `yes` / `on` (case-insensitive);
/// the raw values are returned and the truthy check happens on the frontend.
#[tauri::command]
pub fn get_experimental_env_status() -> HashMap<String, String> {
const VARS: [&str; 5] = [
"KIMI_CODE_EXPERIMENTAL_FLAG",
"KIMI_CODE_EXPERIMENTAL_SECONDARY_MODEL",
"KIMI_CODE_EXPERIMENTAL_TOOL_SELECT",
"KIMI_CODE_EXPERIMENTAL_ACP_V2",
"KIMI_CODE_EXPERIMENTAL_PERSISTENCE_MINIDB_READMODEL",
const VARS: [(&str, &str); 12] = [
("secondary-model", "KIMI_CODE_EXPERIMENTAL_SECONDARY_MODEL"),
("tool-select", "KIMI_CODE_EXPERIMENTAL_TOOL_SELECT"),
(
"persistence_minidb_readmodel",
"KIMI_CODE_EXPERIMENTAL_PERSISTENCE_MINIDB_READMODEL",
),
("tower", "KIMI_CODE_EXPERIMENTAL_TOWER"),
("subagent_fork", "KIMI_CODE_EXPERIMENTAL_SUBAGENT_FORK"),
("wait_for", "KIMI_CODE_EXPERIMENTAL_WAIT_FOR"),
("auto_session_title", "KIMI_CODE_EXPERIMENTAL_AUTO_SESSION_TITLE"),
("remote-control", "KIMI_CODE_EXPERIMENTAL_REMOTE_CONTROL"),
("search_worker", "KIMI_CODE_EXPERIMENTAL_SEARCH_WORKER"),
("file_history", "KIMI_CODE_EXPERIMENTAL_FILE_HISTORY"),
// Non-flag probes consumed by the frontend:
("master", "KIMI_CODE_EXPERIMENTAL_FLAG"),
("legacy", "KIMI_CODE_LEGACY_FLAG"),
];
let mut out = HashMap::new();
for name in VARS {
for (_, name) in VARS {
if let Ok(value) = std::env::var(name) {
if !value.trim().is_empty() {
out.insert(name.to_string(), value);
+343 -34
View File
@@ -1234,6 +1234,49 @@ fn read_state_safe(session_dir: &Path) -> (Option<String>, Option<String>, Optio
(None, None, None, None)
}
/// Whether a session is archived per its `state.json` metadata: the
/// kimi-code v2 engine writes `archived: true` (plus an `archivedAt` epoch-ms
/// timestamp) when archiving and clears both on restore. Unparseable or
/// missing state.json counts as not archived (and won't panic).
fn read_state_archived(session_dir: &Path) -> bool {
let sp = session_dir.join("state.json");
let Ok(content) = fs::read_to_string(&sp) else { return false };
let Ok(obj) = serde_json::from_str::<serde_json::Value>(&content) else { return false };
obj.get("archived").and_then(|v| v.as_bool()).unwrap_or(false)
}
/// Set or clear the archived metadata on a session's `state.json`, preserving
/// every other field. Mirrors upstream kimi-code v2 `SessionMetadata.setArchived`:
/// archive writes `{ archived: true, archivedAt: Date.now() }` (epoch ms, same
/// `Date.now()` format as the CLI), restore writes `{ archived: false }` and
/// drops the `archivedAt` key; `updatedAt` is untouched in both cases.
/// The write is atomic (tmp file + rename), same pattern as the plugin store.
/// Missing or malformed state.json returns a descriptive error, never a panic.
fn set_session_archived_meta(session_dir: &Path, archived: bool) -> Result<(), String> {
let sp = session_dir.join("state.json");
let content = fs::read_to_string(&sp).map_err(|e| format!("read state.json: {e}"))?;
let mut obj: serde_json::Value =
serde_json::from_str(&content).map_err(|e| format!("parse state.json: {e}"))?;
let obj = obj
.as_object_mut()
.ok_or_else(|| "state.json is not a JSON object".to_string())?;
obj.insert("archived".into(), serde_json::Value::Bool(archived));
if archived {
let now_ms = std::time::SystemTime::now()
.duration_since(std::time::UNIX_EPOCH)
.unwrap_or_default()
.as_millis() as u64;
obj.insert("archivedAt".into(), serde_json::Value::Number(now_ms.into()));
} else {
obj.remove("archivedAt");
}
let out = serde_json::to_string(&obj).map_err(|e| format!("serialize state.json: {e}"))?;
let tmp = sp.with_file_name("state.json.tmp");
fs::write(&tmp, out).map_err(|e| format!("write state.json: {e}"))?;
fs::rename(&tmp, &sp).map_err(|e| format!("commit state.json: {e}"))?;
Ok(())
}
fn humanize_workspace(id: &str) -> String {
let re = Regex::new(r"^wd_(.+)_[0-9a-fA-F]{8,}$").unwrap();
if let Some(caps) = re.captures(id) {
@@ -1243,7 +1286,11 @@ fn humanize_workspace(id: &str) -> String {
}
}
fn list_sessions_in_dir(dir: &Path, workspace_id: &str, status: &str) -> Vec<SessionRow> {
/// List session rows under one directory. `in_archive_dir` marks `.kcd-archive`
/// (legacy physical archive); a session is additionally archived when its own
/// `state.json` carries `archived: true` — so CLI-v2 metadata-archived sessions
/// that still live at the active root are correctly classified.
fn list_sessions_in_dir(dir: &Path, workspace_id: &str, in_archive_dir: bool) -> Vec<SessionRow> {
let mut sessions = Vec::new();
if !dir.exists() { return sessions; }
let re = session_re();
@@ -1251,6 +1298,8 @@ fn list_sessions_in_dir(dir: &Path, workspace_id: &str, status: &str) -> Vec<Ses
if !entry.file_type().map(|t| t.is_dir()).unwrap_or(false) { continue; }
let name = entry.file_name().to_string_lossy().to_string();
if !re.is_match(&name) { continue; }
let archived = in_archive_dir || read_state_archived(&entry.path());
let status = if archived { "archived" } else { "active" };
let (title, work_dir, created_at, updated_at) = read_state_safe(&entry.path());
let (bytes, files) = file_size_approx(&entry.path());
let mtime = entry.path().metadata().ok().and_then(|m| m.modified().ok())
@@ -1311,19 +1360,33 @@ fn list_sessions_cmd(home: &Path, status: &str, workspace_filter: Option<String>
let active_dir = root.join(wid);
let arch_dir = archive_root.join(wid);
let active_all = list_sessions_in_dir(&active_dir, wid, "active");
let arch_all = list_sessions_in_dir(&arch_dir, wid, "archived");
let active_list = if status == "archived" { vec![] } else { active_all.clone() };
let arch_list = if status == "active" { vec![] } else { arch_all.clone() };
// Merge both sources, deduping by session id (ids are UUIDs and never
// reused; a stale legacy copy under .kcd-archive loses to the entry at
// the active root). Status comes from each row, so metadata-archived
// sessions surface in the archived filter and the archive-only counts.
let mut by_id: HashMap<String, SessionRow> = HashMap::new();
for row in list_sessions_in_dir(&active_dir, wid, false) {
by_id.insert(row.id.clone(), row);
}
for row in list_sessions_in_dir(&arch_dir, wid, true) {
by_id.entry(row.id.clone()).or_insert(row);
}
let all: Vec<SessionRow> = by_id.into_values().collect();
let active_count = all.iter().filter(|s| s.status == "active").count();
let archived_count = all.iter().filter(|s| s.status == "archived").count();
let listed: Vec<SessionRow> = match status {
"active" => all.iter().filter(|s| s.status == "active").cloned().collect(),
"archived" => all.iter().filter(|s| s.status == "archived").cloned().collect(),
_ => all,
};
let empty = active_all.is_empty() && arch_all.is_empty();
let empty = active_count == 0 && archived_count == 0;
workspaces.push(WorkspaceRow {
id: wid.clone(), name, root: root_path,
created_at: None, last_opened_at: None,
active_count: active_all.len(), archived_count: arch_all.len(), empty,
active_count, archived_count, empty,
});
all_sessions.extend(active_list);
all_sessions.extend(arch_list);
all_sessions.extend(listed);
}
all_sessions.sort_by(|a, b| {
@@ -1356,38 +1419,57 @@ fn assert_safe_path(home: &Path, workspace_id: &str, session_id: &str) -> Result
}
fn archive_session_cmd(home: &Path, workspace_id: &str, session_id: &str) -> Result<ActionResponse, String> {
let src = assert_safe_path(home, workspace_id, session_id)?;
let dest = sessions_root(home).join(".kcd-archive").join(workspace_id).join(session_id);
if !src.exists() { return Err("session not found".into()); }
if let Some(parent) = dest.parent() {
fs::create_dir_all(parent).map_err(|e| format!("mkdir: {}", e))?;
let dir = assert_safe_path(home, workspace_id, session_id)?;
if !dir.exists() { return Err("session not found".into()); }
// Metadata archive, matching upstream kimi-code v2: write `archived: true`
// + `archivedAt` into state.json, leave the session directory in place, and
// do NOT touch session_index.jsonl — archived state is derived from
// state.json, and the CLI reconciles its own index mirror. A session
// without a readable state.json gets a clear error rather than a panic.
let sp = dir.join("state.json");
if !sp.is_file() {
return Err(format!("session {session_id} has no state.json; cannot archive"));
}
fs::rename(&src, &dest).or_else(|_| {
// cross-device fallback
fs_extra::dir::copy(&src, dest.parent().unwrap(), &Default::default()).ok();
fs::remove_dir_all(&src).ok();
Ok::<(), String>(())
}).map_err(|e: String| format!("move: {}", e))?;
scrub_session_index(home, session_id);
set_session_archived_meta(&dir, true)?;
Ok(ActionResponse {
ok: true, workspace_id: workspace_id.to_string(),
session_id: session_id.to_string(), status: Some("archived".into()),
path: Some(dest.to_string_lossy().to_string()), deleted: None,
path: Some(dir.to_string_lossy().to_string()), deleted: None,
})
}
fn unarchive_session_cmd(home: &Path, workspace_id: &str, session_id: &str) -> Result<ActionResponse, String> {
let src = sessions_root(home).join(".kcd-archive").join(workspace_id).join(session_id);
let dest = assert_safe_path(home, workspace_id, session_id)?;
if !src.exists() { return Err("archived session not found".into()); }
if let Some(parent) = dest.parent() {
fs::create_dir_all(parent).map_err(|e| format!("mkdir: {}", e))?;
// 1) Legacy recovery: sessions physically moved to .kcd-archive by older
// KimiSwitch versions are moved back, then their metadata flag is
// cleared per upstream restore semantics (archived:false + archivedAt
// dropped). A missing state.json is fine here — there is no flag.
let archived_dir = sessions_root(home).join(".kcd-archive").join(workspace_id).join(session_id);
if archived_dir.exists() {
if let Some(parent) = dest.parent() {
fs::create_dir_all(parent).map_err(|e| format!("mkdir: {}", e))?;
}
fs::rename(&archived_dir, &dest).or_else(|_| {
// cross-device fallback
fs_extra::dir::copy(&archived_dir, dest.parent().unwrap(), &Default::default()).ok();
fs::remove_dir_all(&archived_dir).ok();
Ok::<(), String>(())
}).map_err(|e: String| format!("move: {}", e))?;
// The move already restored the session; a corrupt state.json must not
// turn a successful restore into an error — the session simply lists
// as active with its flag intact.
if dest.join("state.json").is_file() {
let _ = set_session_archived_meta(&dest, false);
}
return Ok(ActionResponse {
ok: true, workspace_id: workspace_id.to_string(),
session_id: session_id.to_string(), status: Some("active".into()),
path: Some(dest.to_string_lossy().to_string()), deleted: None,
});
}
fs::rename(&src, &dest).or_else(|_| {
fs_extra::dir::copy(&src, dest.parent().unwrap(), &Default::default()).ok();
fs::remove_dir_all(&src).ok();
Ok::<(), String>(())
}).map_err(|e: String| format!("move: {}", e))?;
// 2) Metadata-archived session: still at the active root, just clear the flag.
if !dest.exists() { return Err("archived session not found".into()); }
set_session_archived_meta(&dest, false)?;
Ok(ActionResponse {
ok: true, workspace_id: workspace_id.to_string(),
session_id: session_id.to_string(), status: Some("active".into()),
@@ -1398,6 +1480,9 @@ fn unarchive_session_cmd(home: &Path, workspace_id: &str, session_id: &str) -> R
fn delete_session_cmd(home: &Path, workspace_id: &str, session_id: &str, status_hint: Option<&str>) -> Result<ActionResponse, String> {
let active = assert_safe_path(home, workspace_id, session_id)?;
let archived = sessions_root(home).join(".kcd-archive").join(workspace_id).join(session_id);
// Metadata-archived sessions still live at the active root, so a
// status_hint of "archived" with no legacy .kcd-archive copy falls through
// to the default arm and removes the in-place directory.
let target = match status_hint {
Some("archived") if archived.exists() => archived,
Some("active") if active.exists() => active,
@@ -1440,11 +1525,11 @@ fn delete_workspace_cmd(home: &Path, workspace_id: &str, _confirm: bool, _force:
let arch_dir = root.join(".kcd-archive").join(workspace_id);
if active_dir.exists() {
let active_list = list_sessions_in_dir(&active_dir, workspace_id, "active");
let active_list = list_sessions_in_dir(&active_dir, workspace_id, false);
if !active_list.is_empty() { return Err("workspace is not empty; archive/delete sessions first".into()); }
}
if arch_dir.exists() {
let arch_list = list_sessions_in_dir(&arch_dir, workspace_id, "archived");
let arch_list = list_sessions_in_dir(&arch_dir, workspace_id, true);
if !arch_list.is_empty() { return Err("workspace is not empty; archive/delete sessions first".into()); }
}
@@ -1546,6 +1631,10 @@ fn get_session_preview_cmd(home: &Path, workspace_id: &str, session_id: &str, st
let archived = root.join(".kcd-archive").join(workspace_id).join(session_id);
let session_dir = match status_hint {
Some("archived") if archived.exists() => archived,
// Metadata-archived sessions stay at the active root (kimi-code v2
// writes state.json.archived, no physical move) — read them in place.
Some("archived") if active.exists() => active,
Some("active") if active.exists() => active,
_ => if active.exists() { active } else if archived.exists() { archived }
else { return Err("session not found".into()); }
};
@@ -1666,7 +1755,11 @@ fn get_session_preview_cmd(home: &Path, workspace_id: &str, session_id: &str, st
Ok(PreviewResult {
workspace_id: workspace_id.to_string(),
session_id: session_id.to_string(),
status: if session_dir.to_string_lossy().contains(".kcd-archive") { "archived".into() } else { "active".into() },
status: if session_dir.to_string_lossy().contains(".kcd-archive") || read_state_archived(&session_dir) {
"archived".into()
} else {
"active".into()
},
title, work_dir, created_at, updated_at,
message_count: messages.len(),
truncated,
@@ -1998,3 +2091,219 @@ mod pricing_tests {
assert_eq!(ch, 0.11);
}
}
#[cfg(test)]
mod session_tests {
use super::*;
const WID: &str = "wd_proj_a1b2c3d4e5f6";
const SID: &str = "session_11111111-2222-3333-4444-555555555555";
fn setup_home() -> (tempfile::TempDir, PathBuf) {
let td = tempfile::tempdir().unwrap();
let home = td.path().join("home");
fs::create_dir_all(home.join("sessions").join(WID)).unwrap();
(td, home)
}
fn active_dir(home: &Path) -> PathBuf {
home.join("sessions").join(WID)
}
fn legacy_arch_dir(home: &Path) -> PathBuf {
home.join("sessions").join(".kcd-archive").join(WID)
}
fn write_state(session_dir: &Path, archived: bool, archived_at: Option<u64>) {
let mut obj = serde_json::json!({
"id": SID,
"version": 2,
"cwd": "/tmp/work",
"createdAt": 1_700_000_000_000u64,
"updatedAt": 1_700_000_000_000u64,
"archived": archived,
"title": "test session",
});
let o = obj.as_object_mut().unwrap();
match archived_at {
Some(at) => { o.insert("archivedAt".into(), serde_json::json!(at)); }
None => { o.remove("archivedAt"); }
}
fs::write(session_dir.join("state.json"), serde_json::to_string(&obj).unwrap()).unwrap();
}
fn read_state_json(session_dir: &Path) -> serde_json::Value {
serde_json::from_str(&fs::read_to_string(session_dir.join("state.json")).unwrap()).unwrap()
}
#[test]
fn metadata_archive_roundtrip() {
let (_td, home) = setup_home();
let dir = active_dir(&home).join(SID);
fs::create_dir_all(&dir).unwrap();
write_state(&dir, false, None);
// Fresh session lists as active.
let res = list_sessions_cmd(&home, "all", None);
assert_eq!(res.sessions.len(), 1);
assert_eq!(res.sessions[0].status, "active");
assert_eq!(res.workspaces[0].active_count, 1);
assert_eq!(res.workspaces[0].archived_count, 0);
// Archive is metadata-only: dir stays put, flag + epoch-ms archivedAt written.
let ar = archive_session_cmd(&home, WID, SID).unwrap();
assert_eq!(ar.status.as_deref(), Some("archived"));
assert!(dir.exists(), "metadata archive must not move the session dir");
assert!(!legacy_arch_dir(&home).join(SID).exists(), "nothing moves into .kcd-archive");
let st = read_state_json(&dir);
assert_eq!(st["archived"], true);
let archived_at = st["archivedAt"].as_u64().expect("archivedAt as epoch ms");
assert!(archived_at > 0, "archivedAt is a Date.now()-style epoch-ms number");
// List reflects the new status.
let res = list_sessions_cmd(&home, "all", None);
assert_eq!(res.sessions[0].status, "archived");
assert_eq!(res.workspaces[0].active_count, 0);
assert_eq!(res.workspaces[0].archived_count, 1);
assert!(list_sessions_cmd(&home, "active", None).sessions.is_empty());
assert_eq!(list_sessions_cmd(&home, "archived", None).sessions.len(), 1);
// Unarchive clears the flag in place (archived:false, archivedAt dropped).
let ur = unarchive_session_cmd(&home, WID, SID).unwrap();
assert_eq!(ur.status.as_deref(), Some("active"));
assert!(dir.exists(), "unarchive must not move the dir either");
let st = read_state_json(&dir);
assert_eq!(st["archived"], false);
assert!(st.get("archivedAt").is_none(), "archivedAt key removed on restore");
let res = list_sessions_cmd(&home, "all", None);
assert_eq!(res.sessions[0].status, "active");
assert_eq!(res.workspaces[0].active_count, 1);
assert_eq!(res.workspaces[0].archived_count, 0);
}
#[test]
fn metadata_archive_preserves_other_state_fields() {
let (_td, home) = setup_home();
let dir = active_dir(&home).join(SID);
fs::create_dir_all(&dir).unwrap();
let mut obj = serde_json::json!({
"id": SID,
"version": 2,
"cwd": "/repo",
"createdAt": 1,
"updatedAt": 2,
"archived": false,
"title": "keep me",
"custom": { "goal": "x" },
"agents": { "main": { "type": "main" } },
});
obj.as_object_mut().unwrap().insert("someFutureField".into(), serde_json::json!([1, 2, 3]));
fs::write(dir.join("state.json"), serde_json::to_string(&obj).unwrap()).unwrap();
archive_session_cmd(&home, WID, SID).unwrap();
unarchive_session_cmd(&home, WID, SID).unwrap();
let st = read_state_json(&dir);
assert_eq!(st["title"], "keep me");
assert_eq!(st["custom"]["goal"], "x");
assert_eq!(st["agents"]["main"]["type"], "main");
assert_eq!(st["someFutureField"][0], 1);
assert_eq!(st["updatedAt"], 2, "updatedAt untouched, like upstream touchUpdatedAt:false");
}
#[test]
fn cli_archived_session_in_active_root_lists_as_archived() {
// A session already carrying archived:true in state.json while still
// living at the active root (written by kimi-code CLI v2 itself) must
// surface in the archived filter / counts.
let (_td, home) = setup_home();
let dir = active_dir(&home).join(SID);
fs::create_dir_all(&dir).unwrap();
write_state(&dir, true, Some(1_700_000_000_000u64));
fs::write(dir.join("wire.jsonl"), "").unwrap();
let res = list_sessions_cmd(&home, "all", None);
assert_eq!(res.sessions.len(), 1);
assert_eq!(res.sessions[0].status, "archived");
assert_eq!(res.workspaces[0].active_count, 0);
assert_eq!(res.workspaces[0].archived_count, 1);
assert!(list_sessions_cmd(&home, "active", None).sessions.is_empty());
assert_eq!(list_sessions_cmd(&home, "archived", None).sessions.len(), 1);
// Preview resolves it in place with status "archived".
let pv = get_session_preview_cmd(&home, WID, SID, Some("archived")).unwrap();
assert_eq!(pv.status, "archived");
}
#[test]
fn legacy_kcd_archive_dir_still_listed_and_restored() {
let (_td, home) = setup_home();
let arch_dir = legacy_arch_dir(&home).join(SID);
fs::create_dir_all(&arch_dir).unwrap();
write_state(&arch_dir, false, None);
// Legacy physical archive still shows as archived.
let res = list_sessions_cmd(&home, "all", None);
assert_eq!(res.sessions.len(), 1);
assert_eq!(res.sessions[0].status, "archived");
assert_eq!(res.workspaces[0].active_count, 0);
assert_eq!(res.workspaces[0].archived_count, 1);
assert!(list_sessions_cmd(&home, "active", None).sessions.is_empty());
// Unarchive moves it back and clears the flag.
let ur = unarchive_session_cmd(&home, WID, SID).unwrap();
assert_eq!(ur.status.as_deref(), Some("active"));
assert!(!arch_dir.exists(), "legacy .kcd-archive copy moved back");
let restored = active_dir(&home).join(SID);
assert!(restored.exists());
let st = read_state_json(&restored);
assert_eq!(st["archived"], false);
assert!(st.get("archivedAt").is_none());
let res = list_sessions_cmd(&home, "all", None);
assert_eq!(res.sessions[0].status, "active");
assert_eq!(res.workspaces[0].active_count, 1);
assert_eq!(res.workspaces[0].archived_count, 0);
}
#[test]
fn corrupt_state_json_archive_errors_without_panic() {
let (_td, home) = setup_home();
let dir = active_dir(&home).join(SID);
fs::create_dir_all(&dir).unwrap();
fs::write(dir.join("state.json"), "{ this is not json").unwrap();
let err = archive_session_cmd(&home, WID, SID).unwrap_err();
assert!(err.contains("state.json"), "clear error mentioning state.json, got: {err}");
assert!(dir.exists(), "failed archive leaves the session dir in place");
assert_eq!(fs::read_to_string(dir.join("state.json")).unwrap(), "{ this is not json");
}
#[test]
fn missing_state_json_archive_errors_without_panic() {
let (_td, home) = setup_home();
let dir = active_dir(&home).join(SID);
fs::create_dir_all(&dir).unwrap();
let err = archive_session_cmd(&home, WID, SID).unwrap_err();
assert!(err.contains("no state.json"), "clear error, got: {err}");
assert!(dir.exists());
}
#[test]
fn delete_session_covers_metadata_archived() {
// Status hint "archived" without a legacy .kcd-archive copy falls back
// to removing the metadata-archived in-place directory.
let (_td, home) = setup_home();
let dir = active_dir(&home).join(SID);
fs::create_dir_all(&dir).unwrap();
write_state(&dir, true, Some(1_700_000_000_000u64));
let del = delete_session_cmd(&home, WID, SID, Some("archived")).unwrap();
assert_eq!(del.deleted, Some(true));
assert!(!dir.exists(), "metadata-archived session deleted in place");
assert!(!legacy_arch_dir(&home).join(SID).exists());
assert!(list_sessions_cmd(&home, "all", None).sessions.is_empty());
}
}
+4 -8
View File
@@ -207,6 +207,9 @@ pub fn load_config(agent: &Agent) -> DbResult<Config> {
providers,
models,
raw_other: Value::Null,
// The SQLite snapshot stores no import baseline; an empty baseline
// makes export's stale-key cleanup a no-op (safe degradation).
imported_section_keys: Vec::new(),
})
}
@@ -328,12 +331,5 @@ pub fn delete_setting_pub(key: &str) -> DbResult<()> {
}
fn provider_type_for_str(s: &str) -> ProviderType {
match s {
"anthropic" => ProviderType::Anthropic,
"openai" => ProviderType::Openai,
"openai_responses" => ProviderType::OpenaiResponses,
"google-genai" => ProviderType::GoogleGenai,
"vertexai" => ProviderType::Vertexai,
_ => ProviderType::Kimi,
}
ProviderType::from_kimi_type(s)
}
+224 -24
View File
@@ -148,7 +148,7 @@ pub fn kimi_code_to_config(value: &TomlValue) -> Config {
let provider_type = table
.get("type")
.and_then(|v| v.as_str())
.map(provider_type_for_kimi_type)
.map(ProviderType::from_kimi_type)
.unwrap_or(ProviderType::Kimi);
let base_url = table.get("base_url").and_then(|v| v.as_str()).map(|s| s.to_string());
@@ -216,19 +216,23 @@ pub fn kimi_code_to_config(value: &TomlValue) -> Config {
}
}
let raw_other = {
let mut rest = root;
rest.remove("default_model");
rest.remove("providers");
rest.remove("models");
toml_value_to_json(&TomlValue::Table(rest))
};
let mut rest = root;
rest.remove("default_model");
rest.remove("providers");
rest.remove("models");
// Baseline of top-level keys seen at import time (table order). Export
// only drops baseline keys that later disappeared from raw_other, i.e.
// sections the user removed in the UI — sections the CLI adds after
// import are not in the baseline and survive the round-trip.
let imported_section_keys: Vec<String> = rest.keys().cloned().collect();
let raw_other = toml_value_to_json(&TomlValue::Table(rest));
Config {
default_model,
providers,
models,
raw_other,
imported_section_keys,
}
}
@@ -261,7 +265,15 @@ pub fn config_to_kimi_code(config: &Config, existing: Option<&TomlValue>) -> Tom
if let Some(base_url) = provider.base_url.clone().filter(|s| !s.is_empty()) {
pt.insert("base_url".to_string(), TomlValue::String(base_url));
}
if let Some(api_key) = provider.api_key.clone().filter(|s| !s.is_empty()) {
// Managed (OAuth) providers persist an empty api_key line so the block
// matches the official CLI's provisioned shape (apiKey: ''). A
// user-set api_key on a managed provider (api_key outranks OAuth in
// the CLI's credential priority) must survive the round-trip.
if provider.managed
&& provider.api_key.as_deref().map_or(true, |s| s.is_empty())
{
pt.insert("api_key".to_string(), TomlValue::String("".to_string()));
} else if let Some(api_key) = provider.api_key.clone().filter(|s| !s.is_empty()) {
pt.insert("api_key".to_string(), TomlValue::String(api_key));
}
pt.insert("enabled".to_string(), TomlValue::Boolean(provider.enabled));
@@ -346,10 +358,13 @@ pub fn config_to_kimi_code(config: &Config, existing: Option<&TomlValue>) -> Tom
// Sync UI-managed top-level sections (thinking, experimental,
// secondary_model, ...) from config.raw_other back into the root.
// At import time every top-level key except default_model/providers/
// models was collected into raw_other, so raw_other is the authoritative
// snapshot of those sections. This both persists UI edits to those
// sections and drops sections the user explicitly removed (absent from
// raw_other but still present in `existing`).
// models was collected into raw_other, and their keys recorded in
// `imported_section_keys` (the import-time baseline). Keys present in
// raw_other are written back (persisting UI edits); keys that were in
// the baseline but are absent from raw_other were removed by the user
// and are dropped from `existing`. Top-level keys NOT in the baseline
// were added by the CLI after import and are preserved untouched. An
// empty baseline (Config not built via import) deletes nothing.
let mut managed_keys = std::collections::HashSet::new();
if let TomlValue::Table(extra) =
json_to_toml(&config.raw_other).unwrap_or(TomlValue::Table(Table::new()))
@@ -369,6 +384,7 @@ pub fn config_to_kimi_code(config: &Config, existing: Option<&TomlValue>) -> Tom
&& *k != "providers"
&& *k != "models"
&& !managed_keys.contains(*k)
&& config.imported_section_keys.iter().any(|b| b == *k)
})
.cloned()
.collect();
@@ -379,17 +395,6 @@ pub fn config_to_kimi_code(config: &Config, existing: Option<&TomlValue>) -> Tom
TomlValue::Table(root)
}
fn provider_type_for_kimi_type(typ: &str) -> ProviderType {
match typ {
"anthropic" => ProviderType::Anthropic,
"openai" => ProviderType::Openai,
"openai_responses" => ProviderType::OpenaiResponses,
"google-genai" => ProviderType::GoogleGenai,
"vertexai" => ProviderType::Vertexai,
_ => ProviderType::Kimi,
}
}
fn toml_value_to_json(value: &TomlValue) -> Value {
match value {
TomlValue::String(s) => Value::String(s.clone()),
@@ -564,6 +569,7 @@ api_key = ""
providers,
models,
raw_other: Value::Null,
imported_section_keys: Vec::new(),
};
let exported = config_to_kimi_code(&config, None);
@@ -697,6 +703,7 @@ default_effort = "low"
providers,
models,
raw_other: Value::Null,
imported_section_keys: Vec::new(),
};
let exported = config_to_kimi_code(&config, None);
@@ -810,6 +817,7 @@ max_context_size = 1048576
providers,
models: IndexMap::new(),
raw_other: Value::Null,
imported_section_keys: Vec::new(),
};
let exported = config_to_kimi_code(&config, None);
@@ -850,6 +858,7 @@ max_context_size = 1048576
providers,
models: IndexMap::new(),
raw_other: Value::Null,
imported_section_keys: Vec::new(),
};
let exported = config_to_kimi_code(&config, None);
@@ -864,4 +873,195 @@ max_context_size = 1048576
"private default_model must not leak into config.toml"
);
}
#[test]
fn kimi_code_export_managed_api_key_roundtrip() {
// Regression: a managed (OAuth) provider keeps the official provisioned
// shape (empty api_key line) when it has no key, but a user-set api_key
// on a managed provider (api_key outranks OAuth in the CLI's credential
// priority) must survive the round-trip.
let managed_provider = |api_key: Option<&str>| Provider {
name: "managed:kimi-code".to_string(),
provider_type: ProviderType::Kimi,
base_url: Some("https://api.kimi.com/coding/v1".to_string()),
api_key: api_key.map(String::from),
env: IndexMap::new(),
note: None,
official_url: None,
managed: true,
enabled: true,
active: true,
icon: None,
icon_color: None,
raw_other: serde_json::json!({
"oauth": {"storage": "file", "key": "oauth/kimi-code"}
}),
usage_kinds: None,
usage_config: None,
};
// No api_key → the empty provisioned line is written.
let config = Config {
default_model: None,
providers: IndexMap::from([(
"managed:kimi-code".to_string(),
managed_provider(None),
)]),
models: IndexMap::new(),
raw_other: Value::Null,
imported_section_keys: Vec::new(),
};
let exported = config_to_kimi_code(&config, None);
let provider = exported
.as_table().unwrap()
.get("providers").unwrap()
.as_table().unwrap()
.get("managed:kimi-code").unwrap()
.as_table().unwrap();
assert_eq!(provider.get("api_key").and_then(|v| v.as_str()), Some(""));
// User-set api_key on a managed provider survives.
let config = Config {
default_model: None,
providers: IndexMap::from([(
"managed:kimi-code".to_string(),
managed_provider(Some("sk-user-key")),
)]),
models: IndexMap::new(),
raw_other: Value::Null,
imported_section_keys: Vec::new(),
};
let exported = config_to_kimi_code(&config, None);
let provider = exported
.as_table().unwrap()
.get("providers").unwrap()
.as_table().unwrap()
.get("managed:kimi-code").unwrap()
.as_table().unwrap();
assert_eq!(
provider.get("api_key").and_then(|v| v.as_str()),
Some("sk-user-key")
);
}
#[test]
fn kimi_code_unknown_provider_type_roundtrip() {
// A provider `type` string the CLI knows but Kimi Switch does not
// must survive import → export verbatim, not be rewritten to "kimi".
let toml_str = r#"
default_model = "p1/custom-model"
[providers.p1]
type = "custom-xyz"
api_key = "sk-x"
[models."p1/custom-model"]
provider = "p1"
model = "custom-model"
max_context_size = 128000
"#;
let value: TomlValue = toml_str.parse().unwrap();
let config = kimi_code_to_config(&value);
let provider = config.providers.get("p1").unwrap();
assert_eq!(
provider.provider_type,
ProviderType::Unknown("custom-xyz".to_string())
);
let exported = config_to_kimi_code(&config, Some(&value));
let provider = exported
.as_table().unwrap()
.get("providers").unwrap()
.as_table().unwrap()
.get("p1").unwrap()
.as_table().unwrap();
assert_eq!(
provider.get("type").and_then(|v| v.as_str()),
Some("custom-xyz"),
"unknown provider type must round-trip verbatim"
);
}
#[test]
fn kimi_code_export_preserves_sections_added_after_import() {
// Top-level sections the CLI added AFTER we imported (not in the
// import-time baseline) must survive export instead of being wiped
// by the stale-key cleanup.
let imported_str = r#"
default_model = "glm-5.2"
[providers."glmzhongzhuan"]
type = "anthropic"
api_key = "sk-test"
[models."glm-5.2"]
provider = "glmzhongzhuan"
model = "glm-5.2"
max_context_size = 900000
[thinking]
enabled = true
"#;
let imported: TomlValue = imported_str.parse().unwrap();
let config = kimi_code_to_config(&imported);
// The on-disk file now contains an extra [swarm] section the CLI
// wrote after our import.
let existing: TomlValue = format!("{}\n[swarm]\ntimeout_ms = 123\n", imported_str.trim_end())
.parse()
.unwrap();
let exported = config_to_kimi_code(&config, Some(&existing));
let root = exported.as_table().unwrap();
let swarm = root.get("swarm").unwrap().as_table().unwrap();
assert_eq!(
swarm.get("timeout_ms").and_then(|v| v.as_integer()),
Some(123),
"CLI-added [swarm] section must be preserved"
);
// Baseline sections are still synced as before.
let thinking = root.get("thinking").unwrap().as_table().unwrap();
assert_eq!(thinking.get("enabled").and_then(|v| v.as_bool()), Some(true));
}
#[test]
fn kimi_code_export_drops_user_removed_sections() {
// A section that WAS in the import baseline but was removed from
// raw_other (the user deleted it in the UI) must still be dropped
// from the exported file.
let toml_str = r#"
default_model = "glm-5.2"
[providers."glmzhongzhuan"]
type = "anthropic"
api_key = "sk-test"
[models."glm-5.2"]
provider = "glmzhongzhuan"
model = "glm-5.2"
max_context_size = 900000
[thinking]
enabled = true
"#;
let value: TomlValue = toml_str.parse().unwrap();
let mut config = kimi_code_to_config(&value);
assert!(
config.imported_section_keys.contains(&"thinking".to_string()),
"baseline must record the imported [thinking] section"
);
// UI removed the thinking section.
let mut raw = config.raw_other.as_object().unwrap().clone();
raw.remove("thinking");
config.raw_other = Value::Object(raw);
let exported = config_to_kimi_code(&config, Some(&value));
let root = exported.as_table().unwrap();
assert!(
!root.contains_key("thinking"),
"user-removed section must be dropped on export"
);
}
}
+54 -13
View File
@@ -1,5 +1,7 @@
use std::borrow::Cow;
use indexmap::IndexMap;
use serde::{Deserialize, Serialize};
use serde::{Deserialize, Deserializer, Serialize, Serializer};
use serde_json::Value;
/// Target agent whose provider/model config is being edited.
@@ -19,18 +21,35 @@ impl Agent {
}
}
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
#[derive(Debug, Clone, PartialEq, Eq)]
pub enum ProviderType {
Anthropic,
Openai,
#[serde(rename = "openai_responses")]
OpenaiResponses,
#[serde(rename = "google-genai")]
GoogleGenai,
Vertexai,
/// Kept for compatibility; mapped to OpenAI-compatible in Pi.
Kimi,
/// A provider type string the CLI knows but Kimi Switch does not.
/// Kept verbatim so new upstream `type` values survive the round-trip
/// instead of being rewritten to "kimi".
Unknown(String),
}
// Serde is hand-written to keep a pure string wire format: known variants
// map to their CLI string, `Unknown(s)` maps to `s` itself. A derived
// representation would expose the internal variant names.
impl Serialize for ProviderType {
fn serialize<S: Serializer>(&self, serializer: S) -> Result<S::Ok, S::Error> {
serializer.serialize_str(&self.as_str())
}
}
impl<'de> Deserialize<'de> for ProviderType {
fn deserialize<D: Deserializer<'de>>(deserializer: D) -> Result<Self, D::Error> {
let s = String::deserialize(deserializer)?;
Ok(ProviderType::from_kimi_type(&s))
}
}
const fn default_true() -> bool {
@@ -38,14 +57,29 @@ const fn default_true() -> bool {
}
impl ProviderType {
pub fn as_str(&self) -> &'static str {
pub fn as_str(&self) -> Cow<'static, str> {
match self {
ProviderType::Anthropic => "anthropic",
ProviderType::Openai => "openai",
ProviderType::OpenaiResponses => "openai_responses",
ProviderType::GoogleGenai => "google-genai",
ProviderType::Vertexai => "vertexai",
ProviderType::Kimi => "kimi",
ProviderType::Anthropic => Cow::Borrowed("anthropic"),
ProviderType::Openai => Cow::Borrowed("openai"),
ProviderType::OpenaiResponses => Cow::Borrowed("openai_responses"),
ProviderType::GoogleGenai => Cow::Borrowed("google-genai"),
ProviderType::Vertexai => Cow::Borrowed("vertexai"),
ProviderType::Kimi => Cow::Borrowed("kimi"),
ProviderType::Unknown(s) => Cow::Owned(s.clone()),
}
}
/// Map a CLI `type` string to a `ProviderType`; unrecognized values
/// become `Unknown(s)` so the original string round-trips on export.
pub fn from_kimi_type(s: &str) -> ProviderType {
match s {
"anthropic" => ProviderType::Anthropic,
"openai" => ProviderType::Openai,
"openai_responses" => ProviderType::OpenaiResponses,
"google-genai" => ProviderType::GoogleGenai,
"vertexai" => ProviderType::Vertexai,
"kimi" => ProviderType::Kimi,
other => ProviderType::Unknown(other.to_string()),
}
}
@@ -55,7 +89,7 @@ impl ProviderType {
Some("https://api.openai.com/v1")
}
ProviderType::GoogleGenai => Some("https://generativelanguage.googleapis.com"),
ProviderType::Anthropic | ProviderType::Vertexai => None,
ProviderType::Anthropic | ProviderType::Vertexai | ProviderType::Unknown(_) => None,
}
}
@@ -203,6 +237,12 @@ pub struct Config {
pub models: IndexMap<String, Model>,
#[serde(default, skip_serializing_if = "Value::is_null")]
pub raw_other: Value,
/// Top-level section keys captured at import time. Export uses this
/// baseline to distinguish "user removed this section in the UI" from
/// "the CLI added this section after we imported" — only baseline keys
/// absent from the current raw_other are dropped on export.
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub imported_section_keys: Vec<String>,
}
impl PartialEq for Config {
@@ -211,6 +251,7 @@ impl PartialEq for Config {
&& self.providers == other.providers
&& self.models == other.models
&& self.raw_other == other.raw_other
&& self.imported_section_keys == other.imported_section_keys
}
}
+480 -41
View File
@@ -30,7 +30,16 @@
//! 2. user opens the verification URI in a browser and approves;
//! 3. `poll_device_token()` polls POST /api/oauth/token with the device_code
//! grant until the tokens arrive, then writes them to the same
//! `~/.kimi-code/credentials/kimi-code.json` file the CLI uses.
//! `~/.kimi-code/credentials/<key>.json` file the CLI uses.
//!
//! v4 mirrors the official CLI's dual-region OAuth (v0.38.0, #2862): the login
//! flow and credential lookup are scoped by region. The mainland-cn region
//! (default) uses the shared `oauth/kimi-code` slot (`credentials/kimi-code.json`)
//! and persists no `oauthHost`; the global region derives a scoped key
//! `oauth/kimi-code-env-<sha256>` from (oauthHost, baseUrl), writes
//! `credentials/<scoped>.json`, and persists `oauthHost` in config.toml. Usage
//! queries and token refresh resolve their credentials path + refresh endpoint
//! from the provider's oauth ref instead of always assuming mainland.
use serde::{Deserialize, Serialize};
@@ -40,12 +49,181 @@ use crate::kimi_code_io::kimi_code_config_dir;
/// mid-request counts as expired.
const EXPIRY_LEEWAY_SECS: i64 = 30;
/// OAuth token endpoint (confirmed in the official kimi.exe binary).
const TOKEN_ENDPOINT: &str = "https://auth.kimi.com/api/oauth/token";
/// Device authorization endpoint (RFC 8628).
const DEVICE_AUTHORIZATION_ENDPOINT: &str = "https://auth.kimi.com/api/oauth/device_authorization";
/// Region endpoints (mirror `packages/oauth/src/region.ts`).
const CN_OAUTH_HOST: &str = "https://auth.kimi.com";
const CN_BASE_URL: &str = "https://api.kimi.com/coding/v1";
const GLOBAL_OAUTH_HOST: &str = "https://auth.kimi.ai";
const GLOBAL_BASE_URL: &str = "https://api.kimi.ai/coding/v1";
/// Shared mainland credential slot (mirror `KIMI_CODE_OAUTH_KEY`).
const DEFAULT_OAUTH_KEY: &str = "oauth/kimi-code";
/// Prefix of region-scoped credential keys (mirror `KIMI_CODE_SCOPED_OAUTH_KEY_PREFIX`).
const SCOPED_OAUTH_KEY_PREFIX: &str = "oauth/kimi-code-env-";
/// OAuth token endpoint host suffix (remaining path after the oauth host).
const TOKEN_PATH: &str = "/api/oauth/token";
/// Device authorization endpoint suffix (RFC 8628).
const DEVICE_AUTHORIZATION_PATH: &str = "/api/oauth/device_authorization";
/// Public OAuth client id used by the official CLI (from kimi.exe).
const CLIENT_ID: &str = "17e5f671-d194-4dfb-9706-5516cb48c098";
/// The managed Kimi Code provider name in config.toml.
const MANAGED_PROVIDER_NAME: &str = "managed:kimi-code";
/// A Kimi Code account region (mainland `.com` vs global `.ai`).
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub enum KimiRegion {
/// Mainland China — `auth.kimi.com` / `api.kimi.com`.
Cn,
/// International — `auth.kimi.ai` / `api.kimi.ai`.
Global,
}
impl KimiRegion {
/// Parse a region hint from the frontend (`"cn"` default, `"global"`).
pub fn from_opt(s: Option<&str>) -> KimiRegion {
match s.map(|s| s.trim().to_ascii_lowercase()).as_deref() {
Some("global") => KimiRegion::Global,
_ => KimiRegion::Cn,
}
}
pub fn oauth_host(self) -> &'static str {
match self {
KimiRegion::Cn => CN_OAUTH_HOST,
KimiRegion::Global => GLOBAL_OAUTH_HOST,
}
}
/// Managed API base (`/coding/v1`): usages host for this region.
pub fn base_url(self) -> &'static str {
match self {
KimiRegion::Cn => CN_BASE_URL,
KimiRegion::Global => GLOBAL_BASE_URL,
}
}
}
/// The oauth ref stored under a provider's `raw_other["oauth"]`
/// (`storage`/`key`/`oauthHost`), all optional for lenient parsing.
/// `storage` is not read (Kimi Switch only ever uses `file`).
#[derive(Debug, Clone, Default)]
pub struct OAuthRef {
pub key: Option<String>,
pub oauth_host: Option<String>,
}
/// Extract the oauth ref from a provider's `raw_other["oauth"]` block, if any.
pub fn oauth_ref_from_provider(provider: &crate::models::Provider) -> Option<OAuthRef> {
let oauth = provider.raw_other.get("oauth")?.as_object()?;
Some(OAuthRef {
key: oauth.get("key").and_then(|v| v.as_str()).map(String::from),
oauth_host: oauth
.get("oauthHost")
.and_then(|v| v.as_str())
.map(String::from),
})
}
/// Map an oauth credential `key` to the credentials-file storage name, mirroring
/// the official CLI's `resolveKimiTokenStorageName`:
/// - `"kimi-code"` / `"oauth/kimi-code"` → `"kimi-code"` (file kimi-code.json)
/// - `"oauth/<name>"` → `<name>`
/// - `<name>` (no `/`, not `.`-prefixed) → `<name>` verbatim
/// - anything else → Err
pub fn resolve_storage_name(key: &str) -> Result<String, String> {
if key == "kimi-code" || key == DEFAULT_OAUTH_KEY {
return Ok("kimi-code".to_string());
}
if let Some(rest) = key.strip_prefix("oauth/") {
if !rest.is_empty() {
return Ok(rest.to_string());
}
}
if !key.contains('/') && !key.starts_with('.') {
return Ok(key.to_string());
}
Err(format!("Invalid Kimi OAuth token key: {key}"))
}
/// `trim().replace(/\/+$/, '')`, matching the CLI's `normalizeEndpoint`.
fn normalize_endpoint(s: &str) -> String {
s.trim().trim_end_matches('/').to_string()
}
/// Derive the oauth credential key for an (oauth_host, base_url) pair, mirroring
/// the official CLI's `resolveKimiCodeOAuthKey`: the mainland defaults map to the
/// shared `oauth/kimi-code` slot; anything else gets a scoped slot
/// `oauth/kimi-code-env-<sha256>` of `JSON.stringify({oauthHost, baseUrl})`.
///
/// The payload must byte-match JS `JSON.stringify({ oauthHost, baseUrl })`
/// (oauthHost first, no spaces), so it is hand-built with `format!` rather than
/// `serde_json::json!` (which can't guarantee field order or exact whitespace).
pub fn derive_scoped_key(oauth_host: &str, base_url: &str) -> String {
let oauth_host = normalize_endpoint(oauth_host);
let base_url = normalize_endpoint(base_url);
if oauth_host == CN_OAUTH_HOST && base_url == CN_BASE_URL {
return DEFAULT_OAUTH_KEY.to_string();
}
let payload = format!(
"{{\"oauthHost\":\"{oauth_host}\",\"baseUrl\":\"{base_url}\"}}"
);
use sha2::{Digest, Sha256};
let digest = Sha256::digest(payload.as_bytes());
let hex = digest.iter().map(|b| format!("{b:02x}")).collect::<String>();
format!("{SCOPED_OAUTH_KEY_PREFIX}{}", &hex[..16])
}
/// Resolved credential context for a usage query / token refresh: which
/// credentials file to read/write and which OAuth host to refresh against.
struct OAuthContext {
storage_name: String,
oauth_host: String,
}
impl OAuthContext {
/// Resolve from an optional oauth ref + provider base_url.
///
/// - No ref → the legacy mainland default (`credentials/kimi-code.json` +
/// `auth.kimi.com`), so a provider with no oauth block behaves exactly as
/// before the region work.
/// - Ref with a `key` → use that key's storage (scoped slot for global).
/// - Ref with only `oauthHost` (no key) → derive the scoped key from
/// (oauthHost, base_url), matching the CLI's `resolveKimiCodeOAuthRef`.
fn from(oauth_ref: Option<&OAuthRef>, base_url: &str) -> OAuthContext {
let (key, oauth_host) = match oauth_ref {
Some(r) => {
let host = r
.oauth_host
.clone()
.filter(|s| !s.trim().is_empty())
.unwrap_or_else(|| CN_OAUTH_HOST.to_string());
let k = r
.key
.clone()
.filter(|s| !s.trim().is_empty())
.unwrap_or_else(|| derive_scoped_key(&host, base_url));
(k, host)
}
None => (DEFAULT_OAUTH_KEY.to_string(), CN_OAUTH_HOST.to_string()),
};
let storage_name =
resolve_storage_name(&key).unwrap_or_else(|_| "kimi-code".to_string());
OAuthContext {
storage_name,
oauth_host,
}
}
fn token_endpoint(&self) -> String {
format!("{}{TOKEN_PATH}", self.oauth_host.trim_end_matches('/'))
}
}
/// Credentials file path for a given storage name.
fn credentials_path_for_storage(storage_name: &str) -> std::path::PathBuf {
kimi_code_config_dir()
.join("credentials")
.join(format!("{storage_name}.json"))
}
/// Refresh request timeout; refresh is rare, a bit more headroom than the 8s
/// query default is fine.
const REFRESH_TIMEOUT: std::time::Duration = std::time::Duration::from_secs(10);
@@ -80,17 +258,11 @@ impl OAuthCredentials {
}
}
fn credentials_path() -> std::path::PathBuf {
kimi_code_config_dir()
.join("credentials")
.join("kimi-code.json")
}
/// Load the Kimi Code OAuth session. Errors are deterministic (missing file /
/// unreadable JSON), never transient — the caller turns them into
/// `Ok(success:false)`.
pub fn load_kimi_code_credentials() -> Result<OAuthCredentials, String> {
let path = credentials_path();
/// Load OAuth session from the credentials file for a storage name. Errors are
/// deterministic (missing file / unreadable JSON), never transient — the caller
/// turns them into `Ok(success:false)`.
fn load_credentials_for_storage(storage_name: &str) -> Result<OAuthCredentials, String> {
let path = credentials_path_for_storage(storage_name);
let content = std::fs::read_to_string(&path).map_err(|e| {
format!(
"Kimi Code OAuth credentials not found at {}: {e}. Run `kimi login` first.",
@@ -101,6 +273,11 @@ pub fn load_kimi_code_credentials() -> Result<OAuthCredentials, String> {
.map_err(|e| format!("Failed to parse Kimi Code OAuth credentials: {e}"))
}
/// Load the legacy mainland Kimi Code OAuth session (`kimi-code.json`).
pub fn load_kimi_code_credentials() -> Result<OAuthCredentials, String> {
load_credentials_for_storage("kimi-code")
}
#[derive(Debug, Deserialize)]
struct TokenResponse {
access_token: String,
@@ -118,10 +295,16 @@ fn refresh_lock() -> &'static tokio::sync::Mutex<()> {
}
/// Return a usable access token, refreshing via the refresh_token grant when
/// the stored one is expired. Errors are deterministic (missing/dead session)
/// — the caller surfaces them as `Ok(success:false)`.
pub async fn get_valid_access_token() -> Result<String, String> {
let creds = load_kimi_code_credentials()?;
/// the stored one is expired. The credential file and refresh endpoint are
/// resolved from the provider's oauth ref + base_url (see [`OAuthContext`]);
/// with no ref this is the legacy mainland default. Errors are deterministic
/// (missing/dead session) — the caller surfaces them as `Ok(success:false)`.
pub async fn get_valid_access_token(
oauth_ref: Option<&OAuthRef>,
base_url: &str,
) -> Result<String, String> {
let ctx = OAuthContext::from(oauth_ref, base_url);
let creds = load_credentials_for_storage(&ctx.storage_name)?;
if !creds.is_expired() {
return Ok(creds.access_token);
}
@@ -129,11 +312,11 @@ pub async fn get_valid_access_token() -> Result<String, String> {
let _guard = refresh_lock().lock().await;
// Re-read under the lock: the CLI or a previous waiter may have refreshed
// while we were waiting.
let creds = load_kimi_code_credentials()?;
let creds = load_credentials_for_storage(&ctx.storage_name)?;
if !creds.is_expired() {
return Ok(creds.access_token);
}
refresh_credentials(&creds).await
refresh_credentials(&creds, &ctx).await
}
/// Merge a token endpoint response into the existing credentials JSON,
@@ -181,8 +364,9 @@ fn merge_token_response(current_json: &str, resp: &TokenResponse) -> String {
}
/// Call the token endpoint with the refresh_token grant and persist the
/// rotated tokens. Caller must hold [`refresh_lock`].
async fn refresh_credentials(creds: &OAuthCredentials) -> Result<String, String> {
/// rotated tokens. The refresh endpoint + file come from the resolved context.
/// Caller must hold [`refresh_lock`].
async fn refresh_credentials(creds: &OAuthCredentials, ctx: &OAuthContext) -> Result<String, String> {
let refresh_token = creds
.refresh_token
.clone()
@@ -198,7 +382,7 @@ async fn refresh_credentials(creds: &OAuthCredentials) -> Result<String, String>
// Tokens only ever go into the request body — never into logs or errors.
let resp = client
.post(TOKEN_ENDPOINT)
.post(ctx.token_endpoint())
.form(&[
("grant_type", "refresh_token"),
("client_id", CLIENT_ID),
@@ -226,7 +410,7 @@ async fn refresh_credentials(creds: &OAuthCredentials) -> Result<String, String>
// Re-read right before writing: if the CLI refreshed meanwhile, its newer
// (rotated) tokens win — overwriting them would kill its next refresh.
let path = credentials_path();
let path = credentials_path_for_storage(&ctx.storage_name);
let current = std::fs::read_to_string(&path).unwrap_or_default();
if let Ok(latest) = serde_json::from_str::<OAuthCredentials>(&current) {
if !latest.is_expired() && latest.access_token != creds.access_token {
@@ -326,17 +510,20 @@ fn identity_headers() -> Vec<(&'static str, String)> {
headers
}
/// Step 1 of the device flow: ask the server for a user_code + device_code.
/// No user interaction required here; the frontend shows the code + URL.
pub async fn start_device_authorization() -> Result<DeviceAuthorization, String> {
/// Step 1 of the device flow: ask the region's server for a user_code +
/// device_code. No user interaction required here; the frontend shows the
/// code + URL.
pub async fn start_device_authorization(region: KimiRegion) -> Result<DeviceAuthorization, String> {
let client = reqwest::Client::builder()
.timeout(REFRESH_TIMEOUT)
.build()
.map_err(|e| format!("Failed to build HTTP client: {e}"))?;
let mut req = client
.post(DEVICE_AUTHORIZATION_ENDPOINT)
.form(&[("client_id", CLIENT_ID)]);
let endpoint = format!(
"{}{DEVICE_AUTHORIZATION_PATH}",
region.oauth_host().trim_end_matches('/')
);
let mut req = client.post(&endpoint).form(&[("client_id", CLIENT_ID)]);
for (name, value) in identity_headers() {
req = req.header(name, value);
}
@@ -356,24 +543,30 @@ pub async fn start_device_authorization() -> Result<DeviceAuthorization, String>
.map_err(|e| format!("Failed to parse device authorization response: {e}"))
}
/// Step 2 of the device flow: poll the token endpoint until the user
/// Step 2 of the device flow: poll the region's token endpoint until the user
/// approves (or the flow fails). On success the tokens are merged into the
/// CLI credentials file, making `kimi login` unnecessary.
/// region's credentials file and the provider is provisioned, making
/// `kimi login` unnecessary.
pub async fn poll_device_token(
device_code: &str,
initial_interval: i64,
region: KimiRegion,
) -> Result<DevicePollStatus, String> {
let client = reqwest::Client::builder()
.timeout(REFRESH_TIMEOUT)
.build()
.map_err(|e| format!("Failed to build HTTP client: {e}"))?;
let token_endpoint = format!(
"{}{TOKEN_PATH}",
region.oauth_host().trim_end_matches('/')
);
let deadline = std::time::Instant::now() + POLL_TIMEOUT;
let mut interval = initial_interval.max(1);
loop {
let mut req = client
.post(TOKEN_ENDPOINT)
.post(&token_endpoint)
.form(&[
("grant_type", DEVICE_GRANT_TYPE),
("client_id", CLIENT_ID),
@@ -393,7 +586,7 @@ pub async fn poll_device_token(
Ok(t) => t,
Err(e) => return Err(format!("Failed to parse token response: {e}")),
};
persist_device_token(&token)?;
persist_device_token(&token, region)?;
return Ok(DevicePollStatus::Success);
}
@@ -424,17 +617,89 @@ pub async fn poll_device_token(
}
}
/// Write a freshly obtained token set into the CLI credentials file,
/// preserving unrelated fields and using the same snake_case shape.
fn persist_device_token(token: &TokenResponse) -> Result<(), String> {
let path = credentials_path();
/// Write a freshly obtained token set into the region's credentials file,
/// preserving unrelated fields and using the same snake_case shape, then
/// provision the managed provider in config.toml (mirroring the CLI).
///
/// cn writes the shared `credentials/kimi-code.json`; global resolves the
/// scoped key from (oauthHost, baseUrl) and writes `credentials/<scoped>.json`.
fn persist_device_token(token: &TokenResponse, region: KimiRegion) -> Result<(), String> {
let key = derive_scoped_key(region.oauth_host(), region.base_url());
let storage_name = resolve_storage_name(&key)?;
let path = credentials_path_for_storage(&storage_name);
if let Some(dir) = path.parent() {
let _ = std::fs::create_dir_all(dir);
}
let current = std::fs::read_to_string(&path).unwrap_or_default();
let merged = merge_token_response(&current, token);
std::fs::write(&path, merged)
.map_err(|e| format!("Failed to write Kimi credentials: {e}"))
.map_err(|e| format!("Failed to write Kimi credentials: {e}"))?;
provision_managed_provider(region, &key)
}
/// Update `[providers."managed:kimi-code"]` in config.toml so the official CLI
/// can use the freshly obtained credentials (mirror the CLI's post-login
/// provisioning / `authService.provisionProvider`): ensure the provider exists,
/// `type="kimi"`, `base_url=<region baseUrl>`, `api_key=""`, and the oauth ref
/// block `{storage="file", key=<region key>}` — `oauthHost` is persisted only
/// for global (cn writes none, so `key == "oauth/kimi-code"` stays the
/// explicit-mainland signal). Other fields (icon, ...) are left untouched; the
/// round-trip preserves every unrelated section.
fn provision_managed_provider(region: KimiRegion, oauth_key: &str) -> Result<(), String> {
use indexmap::IndexMap;
let mut config = crate::kimi_code_io::load_kimi_code_config_as_config()
.map_err(|e| format!("Failed to read Kimi Code config: {e}"))?;
let provider = config
.providers
.entry(MANAGED_PROVIDER_NAME.to_string())
.or_insert_with(|| crate::models::Provider {
name: MANAGED_PROVIDER_NAME.to_string(),
provider_type: crate::models::ProviderType::Kimi,
base_url: None,
api_key: None,
env: IndexMap::new(),
note: None,
official_url: None,
managed: true,
enabled: true,
active: false,
icon: None,
icon_color: None,
raw_other: serde_json::Value::Object(serde_json::Map::new()),
usage_kinds: None,
usage_config: None,
});
provider.provider_type = crate::models::ProviderType::Kimi;
provider.base_url = Some(region.base_url().to_string());
provider.api_key = Some(String::new());
provider.managed = true;
let mut oauth = serde_json::Map::new();
oauth.insert(
"storage".to_string(),
serde_json::Value::String("file".to_string()),
);
oauth.insert(
"key".to_string(),
serde_json::Value::String(oauth_key.to_string()),
);
if region == KimiRegion::Global {
oauth.insert(
"oauthHost".to_string(),
serde_json::Value::String(region.oauth_host().to_string()),
);
}
if let Some(obj) = provider.raw_other.as_object_mut() {
obj.insert("oauth".to_string(), serde_json::Value::Object(oauth));
} else {
provider.raw_other = serde_json::json!({ "oauth": oauth });
}
crate::kimi_code_io::save_config_as_kimi_code(&config)
.map_err(|e| format!("Failed to write Kimi Code config: {e}"))
}
#[cfg(test)]
@@ -569,4 +834,178 @@ mod tests {
let success = serde_json::to_value(DevicePollStatus::Success).unwrap();
assert_eq!(success["status"], "success");
}
// ── region / credential-key resolution ────────────────────────────────
#[test]
fn resolve_storage_name_maps_all_branches() {
// Default slot.
assert_eq!(resolve_storage_name("kimi-code").unwrap(), "kimi-code");
assert_eq!(resolve_storage_name("oauth/kimi-code").unwrap(), "kimi-code");
// oauth/<name> strips the prefix.
assert_eq!(resolve_storage_name("oauth/foo").unwrap(), "foo");
// Bare name without '/' is kept verbatim.
assert_eq!(resolve_storage_name("custom").unwrap(), "custom");
// Invalid keys → Err.
assert!(resolve_storage_name("oauth/").is_err(), "empty suffix");
assert!(resolve_storage_name(".hidden").is_err(), "dot-prefixed");
assert!(resolve_storage_name("a/b").is_err(), "contains slash");
}
#[test]
fn derive_scoped_key_returns_default_for_mainland() {
assert_eq!(
derive_scoped_key("https://auth.kimi.com", "https://api.kimi.com/coding/v1"),
"oauth/kimi-code"
);
// Trailing slashes / whitespace normalize to the defaults.
assert_eq!(
derive_scoped_key(" https://auth.kimi.com/ ", "https://api.kimi.com/coding/v1/"),
"oauth/kimi-code"
);
}
#[test]
fn derive_scoped_key_scopes_by_endpoint_pair() {
let key = derive_scoped_key("https://auth.kimi.ai", "https://api.kimi.ai/coding/v1");
assert!(key.starts_with("oauth/kimi-code-env-"), "key: {key}");
let hex = &key["oauth/kimi-code-env-".len()..];
assert_eq!(hex.len(), 16, "key: {key}");
assert!(hex.chars().all(|c| c.is_ascii_hexdigit()), "key: {key}");
// Byte-exact vs JS JSON.stringify({oauthHost, baseUrl}) — precomputed,
// guards against serde field order / whitespace drift.
assert_eq!(key, "oauth/kimi-code-env-0e4f99c69cc27850");
}
#[test]
fn oauth_context_defaults_without_ref() {
let ctx = OAuthContext::from(None, "https://api.kimi.com/coding/v1");
assert_eq!(ctx.storage_name, "kimi-code");
assert_eq!(ctx.oauth_host, "https://auth.kimi.com");
assert_eq!(ctx.token_endpoint(), "https://auth.kimi.com/api/oauth/token");
}
#[test]
fn oauth_context_defaults_without_ref_even_for_custom_base() {
// Zero-regression: a ref-less provider must keep using the legacy
// mainland slot regardless of its base_url (derive only kicks in when
// an oauth ref carries an oauthHost).
let ctx = OAuthContext::from(None, "https://proxy.example.com/coding/v1");
assert_eq!(ctx.storage_name, "kimi-code");
assert_eq!(ctx.oauth_host, "https://auth.kimi.com");
}
#[test]
fn oauth_context_derives_scoped_key_when_ref_has_only_oauth_host() {
let r = OAuthRef {
key: None,
oauth_host: Some("https://auth.kimi.ai".to_string()),
};
let ctx = OAuthContext::from(Some(&r), "https://api.kimi.ai/coding/v1");
assert_eq!(ctx.storage_name, "kimi-code-env-0e4f99c69cc27850");
assert_eq!(ctx.oauth_host, "https://auth.kimi.ai");
}
#[test]
fn oauth_context_follows_ref_key_and_host() {
let r = OAuthRef {
key: Some("oauth/kimi-code-env-0e4f99c69cc27850".to_string()),
oauth_host: Some("https://auth.kimi.ai".to_string()),
};
let ctx = OAuthContext::from(Some(&r), "https://api.kimi.ai/coding/v1");
assert_eq!(ctx.storage_name, "kimi-code-env-0e4f99c69cc27850");
assert_eq!(ctx.oauth_host, "https://auth.kimi.ai");
assert_eq!(ctx.token_endpoint(), "https://auth.kimi.ai/api/oauth/token");
}
// ── login persistence + provisioning (via KIMI_CODE_HOME temp dir) ─────
/// Run `f` with `KIMI_CODE_HOME` pointed at a fresh temp dir (the config
/// dir). A process-wide mutex serializes env mutation so parallel tests in
/// this binary can't observe a stale override.
fn with_kimi_code_home<T>(f: impl FnOnce(&std::path::Path) -> T) -> T {
static LOCK: std::sync::OnceLock<std::sync::Mutex<()>> = std::sync::OnceLock::new();
let _guard = LOCK.get_or_init(|| std::sync::Mutex::new(())).lock().unwrap();
let home = tempfile::tempdir().unwrap();
std::env::set_var("KIMI_CODE_HOME", home.path());
let out = f(home.path());
std::env::remove_var("KIMI_CODE_HOME");
out
}
#[test]
fn persist_cn_login_writes_default_slot_and_provisions_without_oauth_host() {
with_kimi_code_home(|dir| {
// Pre-existing config with an unrelated section must survive.
std::fs::write(dir.join("config.toml"), "[thinking]\nenabled = true\n").unwrap();
let token = TokenResponse {
access_token: "cn-access".to_string(),
refresh_token: Some("cn-refresh".to_string()),
expires_in: Some(900),
scope: Some("kimi-code".to_string()),
token_type: None,
};
persist_device_token(&token, KimiRegion::Cn).unwrap();
// Credentials land in the shared default slot.
let cred =
std::fs::read_to_string(dir.join("credentials/kimi-code.json")).unwrap();
assert!(cred.contains("cn-access"), "cred: {cred}");
// Provider provisioned with the cn base_url and NO oauthHost.
let cfg_toml = std::fs::read_to_string(dir.join("config.toml")).unwrap();
let cfg: toml::Value = cfg_toml.parse().unwrap();
let provider = &cfg["providers"]["managed:kimi-code"];
assert_eq!(provider["type"].as_str(), Some("kimi"));
assert_eq!(
provider["base_url"].as_str(),
Some("https://api.kimi.com/coding/v1")
);
assert_eq!(provider["api_key"].as_str(), Some(""));
let oauth = &provider["oauth"];
assert_eq!(oauth["storage"].as_str(), Some("file"));
assert_eq!(oauth["key"].as_str(), Some("oauth/kimi-code"));
assert!(
oauth.get("oauthHost").is_none(),
"cn must not persist oauthHost"
);
// Unrelated section preserved by the round-trip.
assert_eq!(cfg["thinking"]["enabled"].as_bool(), Some(true));
});
}
#[test]
fn persist_global_login_writes_scoped_slot_and_provisions_oauth_host() {
with_kimi_code_home(|dir| {
std::fs::write(dir.join("config.toml"), "").unwrap();
let token = TokenResponse {
access_token: "global-access".to_string(),
refresh_token: Some("global-refresh".to_string()),
expires_in: Some(900),
scope: Some("kimi-code".to_string()),
token_type: None,
};
persist_device_token(&token, KimiRegion::Global).unwrap();
let key = derive_scoped_key("https://auth.kimi.ai", "https://api.kimi.ai/coding/v1");
assert_eq!(key, "oauth/kimi-code-env-0e4f99c69cc27850");
let storage = resolve_storage_name(&key).unwrap();
let cred =
std::fs::read_to_string(dir.join(format!("credentials/{storage}.json"))).unwrap();
assert!(cred.contains("global-access"), "cred: {cred}");
let cfg_toml = std::fs::read_to_string(dir.join("config.toml")).unwrap();
let cfg: toml::Value = cfg_toml.parse().unwrap();
let provider = &cfg["providers"]["managed:kimi-code"];
assert_eq!(
provider["base_url"].as_str(),
Some("https://api.kimi.ai/coding/v1")
);
let oauth = &provider["oauth"];
assert_eq!(oauth["key"].as_str(), Some(key.as_str()));
assert_eq!(oauth["oauthHost"].as_str(), Some("https://auth.kimi.ai"));
});
}
}
+5 -2
View File
@@ -205,8 +205,10 @@ pub fn pi_api_for_provider(provider_type: &ProviderType) -> &'static str {
ProviderType::Anthropic => "anthropic-messages",
ProviderType::GoogleGenai => "google-generative-ai",
ProviderType::Vertexai => "google-vertex",
// Treat Kimi as OpenAI-compatible since it is not a native Pi API.
ProviderType::Kimi => "openai-completions",
// Treat Kimi as OpenAI-compatible since it is not a native Pi API;
// unknown upstream types get the same lenient handling (Pi is a
// legacy path).
ProviderType::Kimi | ProviderType::Unknown(_) => "openai-completions",
}
}
@@ -383,6 +385,7 @@ pub fn pi_file_to_config(file: &PiModelsFile) -> Config {
providers,
models,
raw_other: file.extra.clone(),
imported_section_keys: Vec::new(),
}
}
+49 -9
View File
@@ -67,18 +67,30 @@ fn parse_f64(value: &serde_json::Value) -> Option<f64> {
}
// ── Kimi For Coding ─────────────────────────────────────────
// GET https://api.kimi.com/coding/v1/usages
// GET {base_url}/usages
// 默认 https://api.kimi.com/coding/v1/usages
// global: https://api.kimi.ai/coding/v1/usages
// Response: { limits: [{ detail: { limit, remaining, resetTime } }],
// usage: { limit, remaining, resetTime } }
pub async fn query_kimi_coding(api_key: &str, timeout: Duration) -> Result<UsageResult, String> {
match get_json(
"https://api.kimi.com/coding/v1/usages",
api_key,
AuthStyle::Bearer,
timeout,
)
.await?
/// 由 base_url 拼接 usages 查询 URL;base_url 为空/空白时回退大陆默认。
/// 纯函数,便于单测。
fn kimi_coding_usages_url(base_url: &str) -> String {
let base = if base_url.trim().is_empty() {
"https://api.kimi.com/coding/v1"
} else {
base_url.trim_end_matches('/')
};
format!("{base}/usages")
}
pub async fn query_kimi_coding(
base_url: &str,
api_key: &str,
timeout: Duration,
) -> Result<UsageResult, String> {
let url = kimi_coding_usages_url(base_url);
match get_json(&url, api_key, AuthStyle::Bearer, timeout).await?
{
Fetched::Body(body) => {
let tiers = parse_kimi_coding(&body);
@@ -396,6 +408,34 @@ mod tests {
use super::*;
use serde_json::json;
#[test]
fn kimi_coding_usages_url_uses_base_and_falls_back() {
// global base → .ai usages URL
assert_eq!(
kimi_coding_usages_url("https://api.kimi.ai/coding/v1"),
"https://api.kimi.ai/coding/v1/usages"
);
// 尾斜杠去掉
assert_eq!(
kimi_coding_usages_url("https://api.kimi.ai/coding/v1/"),
"https://api.kimi.ai/coding/v1/usages"
);
// 空串/空白回退大陆默认
assert_eq!(
kimi_coding_usages_url(""),
"https://api.kimi.com/coding/v1/usages"
);
assert_eq!(
kimi_coding_usages_url(" "),
"https://api.kimi.com/coding/v1/usages"
);
// 大陆 base 原样拼接
assert_eq!(
kimi_coding_usages_url("https://api.kimi.com/coding/v1"),
"https://api.kimi.com/coding/v1/usages"
);
}
#[test]
fn kimi_coding_flattens_limits_and_usage() {
let body = json!({
+26 -2
View File
@@ -108,7 +108,9 @@ pub fn detect_provider(base_url: &str) -> Vec<UsageKind> {
if url.contains("api.moonshot.cn") || url.contains("api.moonshot.ai") {
kinds.push(UsageKind::BalanceKimi);
}
if url.contains("api.kimi.com") && url.contains("/coding") {
if (url.contains("api.kimi.com") || url.contains("api.kimi.ai"))
&& url.contains("/coding")
{
kinds.push(UsageKind::PlanKimiCoding);
}
if url.contains("open.bigmodel.cn") || url.contains("api.z.ai") {
@@ -169,7 +171,9 @@ pub async fn query_kind(
.unwrap_or(base_url);
balance::query_newapi(url, token, uid, timeout).await
}
UsageKind::PlanKimiCoding => coding_plan::query_kimi_coding(api_key, timeout).await,
UsageKind::PlanKimiCoding => {
coding_plan::query_kimi_coding(base_url, api_key, timeout).await
}
UsageKind::PlanZhipu => coding_plan::query_zhipu(base_url, api_key, timeout).await,
UsageKind::PlanMinimax => {
coding_plan::query_minimax(api_key, !lower.contains("minimax.io"), timeout).await
@@ -222,6 +226,26 @@ mod tests {
assert!(detect_provider("https://api.kimi.com/v1").is_empty());
}
#[test]
fn detect_provider_kimi_coding_matches_global_ai_host() {
// global 站 api.kimi.ai + /coding 命中套餐
assert_eq!(
detect_provider("https://api.kimi.ai/coding/v1"),
vec![UsageKind::PlanKimiCoding]
);
assert_eq!(
detect_provider("https://api.kimi.ai/coding/v1/usages"),
vec![UsageKind::PlanKimiCoding]
);
// api.kimi.ai 但无 /coding 路径 → 不命中(也不命中 Moonshot 余额)
assert!(detect_provider("https://api.kimi.ai/v1").is_empty());
// .com 老路径不受影响
assert_eq!(
detect_provider("https://api.kimi.com/coding/v1"),
vec![UsageKind::PlanKimiCoding]
);
}
#[test]
fn detect_provider_opencode_go_excludes_payg_zen() {
// /zen/go 命中套餐查询
+1 -1
View File
@@ -1,6 +1,6 @@
{
"productName": "Kimi Switch",
"version": "0.7.6",
"version": "0.7.12",
"identifier": "com.kimiswitch.app",
"build": {
"beforeDevCommand": "npm run dev",
+54 -19
View File
@@ -706,18 +706,44 @@ export default function App() {
onModelChange={(model) => {
updateConfig((cfg) => {
const models = { ...cfg.models };
// Auto-fix the placeholder alias from onModelAdd: once the
// real model id is filled in, rename "<provider>/新模型" (and
// the mid-typing "<provider>/<prefix>" states) to
// "<provider>/<model-id>" so the CLI records usage under the
// real model name instead of the placeholder.
let effective = model;
const safeProvider = model.provider.replace(/\//g, "-");
const prefix = `${safeProvider}/`;
const modelId = model.model.trim();
const tail = model.alias.startsWith(prefix)
? model.alias.slice(prefix.length)
: "";
const targetAlias = `${prefix}${modelId}`;
if (
modelId !== "" &&
model.alias !== targetAlias &&
(tail === "新模型" ||
tail.startsWith("新模型-") ||
(tail !== "" && modelId.startsWith(tail))) &&
!(targetAlias in models)
) {
effective = { ...model, alias: targetAlias };
delete models[model.alias];
}
const existingKeys = Object.keys(models).filter(
(k) => models[k].provider === currentProvider.name
);
const oldKey = existingKeys.find((k) =>
model.alias === k ? true : models[k].alias === model.alias
effective.alias === k ? true : models[k].alias === effective.alias
);
if (oldKey && oldKey !== model.alias) {
if (oldKey && oldKey !== effective.alias) {
delete models[oldKey];
}
models[model.alias] = model;
models[effective.alias] = effective;
let default_model = cfg.default_model;
if (default_model === oldKey) default_model = model.alias;
if (default_model === oldKey) default_model = effective.alias;
else if (effective !== model && default_model === model.alias)
default_model = effective.alias;
return { ...cfg, models, default_model };
});
}}
@@ -735,22 +761,31 @@ export default function App() {
}}
onModelAdd={() => {
const safeProvider = currentProvider.name.replace(/\//g, "-");
const alias = `${safeProvider}/新模型`;
updateConfig((cfg) => ({
...cfg,
models: {
...cfg.models,
[alias]: {
alias,
provider: currentProvider.name,
model: "",
max_context_size: getDefaultMaxContextSize(alias),
display_name: null,
supports_1m: false,
capabilities: agent === "kimi_code" ? ["thinking"] : [],
updateConfig((cfg) => {
// Deduplicate the placeholder key: a second "add model" click
// while the previous placeholder is still unedited must not
// silently overwrite it.
let alias = `${safeProvider}/新模型`;
let n = 1;
while (alias in cfg.models) {
alias = `${safeProvider}/新模型-${++n}`;
}
return {
...cfg,
models: {
...cfg.models,
[alias]: {
alias,
provider: currentProvider.name,
model: "",
max_context_size: getDefaultMaxContextSize(alias),
display_name: null,
supports_1m: false,
capabilities: agent === "kimi_code" ? ["thinking"] : [],
},
},
},
}));
};
});
}}
onBulkAdd={(models) => {
updateConfig((cfg) => {
+45 -5
View File
@@ -1,7 +1,14 @@
import { useEffect, useState } from "react";
import { invoke } from "@tauri-apps/api/core";
import { useTranslation } from "../i18n";
import type { TranslationKey } from "../i18n/zh";
import { getAgentSettings, setAgentSettings } from "../lib/agent-settings";
import type { AgentSettings, Hook, PermissionRule } from "../types";
import type {
AgentSettings,
ExperimentalEnvStatus,
Hook,
PermissionRule,
} from "../types";
import { Card, Checkbox, NumberField, Segmented } from "./ui/controls";
interface AgentSettingsPanelProps {
@@ -9,12 +16,12 @@ interface AgentSettingsPanelProps {
onChange: (nextRawOther: unknown) => void;
}
const THINKING_LEVELS = ["low", "medium", "high", "max"] as const;
// Upstream removed the "max" effort tier (auto-migrates to "high").
const THINKING_LEVELS = ["low", "medium", "high"] as const;
const THINKING_LABELS: Record<(typeof THINKING_LEVELS)[number], TranslationKey> = {
low: "thinkingLow",
medium: "thinkingMedium",
high: "thinkingHigh",
max: "thinkingMax",
};
const PERMISSION_DECISIONS = ["allow", "deny", "ask"] as const;
@@ -40,9 +47,23 @@ const COMMON_EVENTS = [
export function AgentSettingsPanel({ rawOther, onChange }: AgentSettingsPanelProps) {
const { t } = useTranslation();
const settings = getAgentSettings(rawOther);
/**
* KIMI_CODE_LEGACY_FLAG=1 keeps the v1 loop_control keys dual-written for
* v1-engine users; the default (v2) writes only max_attempts_per_step.
*/
const [legacyV1, setLegacyV1] = useState(false);
useEffect(() => {
invoke<ExperimentalEnvStatus>("get_experimental_env_status")
.then((env) => {
const value = env?.KIMI_CODE_LEGACY_FLAG ?? "";
setLegacyV1(["1", "true", "yes", "on"].includes(value.trim().toLowerCase()));
})
.catch(() => setLegacyV1(false));
}, []);
const update = (patch: Partial<AgentSettings>) => {
onChange(setAgentSettings(rawOther, patch));
onChange(setAgentSettings(rawOther, patch, { legacyV1 }));
};
const updateThinking = (patch: Partial<AgentSettings["thinking"]>) => {
@@ -95,7 +116,7 @@ export function AgentSettingsPanel({ rawOther, onChange }: AgentSettingsPanelPro
label={t("thinkingKeep")}
checked={settings.thinking?.keep === "all"}
disabled={!thinkingEnabled}
onChange={(checked) => updateThinking({ keep: checked ? "all" : false })}
onChange={(checked) => updateThinking({ keep: checked ? "all" : "off" })}
/>
<p className="text-xs text-content-muted">{t("thinkingContextHint")}</p>
</Card>
@@ -136,6 +157,25 @@ export function AgentSettingsPanel({ rawOther, onChange }: AgentSettingsPanelPro
</Card>
<Card title={t("permissionRules")}>
{/* kimi-code 0.40.1 `[permission] dangerous_command_guard`. The env
var KIMI_CODE_DANGEROUS_COMMAND_GUARD (literal "true"/"false")
outranks this config at runtime; no env-lock UI here (deliberate
minimal scope). Absent key = upstream default on. */}
<Checkbox
label={t("permissionDangerousGuard")}
checked={settings.permission?.dangerous_command_guard ?? true}
onChange={(checked) =>
update({
permission: {
...settings.permission,
dangerous_command_guard: checked,
},
})
}
/>
<p className="text-xs text-content-muted">
{t("permissionDangerousGuardDesc")}
</p>
<div className="space-y-2">
{(settings.permission?.rules ?? []).map((rule, idx) => (
<div key={idx} className="flex items-center gap-2">
+74 -23
View File
@@ -25,6 +25,8 @@ interface KimiOAuthDialogProps {
onClose: () => void;
}
type OAuthRegion = "cn" | "global";
/** Kimi device-code sign-in dialog (in-app `kimi login`). */
export function KimiOAuthDialog({ open, onClose }: KimiOAuthDialogProps) {
const { t } = useTranslation();
@@ -33,10 +35,12 @@ export function KimiOAuthDialog({ open, onClose }: KimiOAuthDialogProps) {
const [done, setDone] = useState(false);
const [error, setError] = useState<string | null>(null);
const [copied, setCopied] = useState(false);
const [region, setRegion] = useState<OAuthRegion>("cn");
const [started, setStarted] = useState(false);
const activeRef = useRef(false);
const intervalRef = useRef(5);
// Start a fresh device authorization when the dialog opens.
// Reset to the "pick a region" screen when the dialog (re)opens.
useEffect(() => {
if (!open) return;
activeRef.current = true;
@@ -45,8 +49,26 @@ export function KimiOAuthDialog({ open, onClose }: KimiOAuthDialogProps) {
setDone(false);
setError(null);
setCopied(false);
setRegion("cn");
setStarted(false);
intervalRef.current = 5;
invoke<DeviceAuthorization>("kimi_oauth_start")
return () => {
activeRef.current = false;
};
}, [open]);
// Begin the device flow for a region. Locks the picker; a later restart is
// the way to switch region.
const start = (r: OAuthRegion) => {
setRegion(r);
setStarted(true);
setAuth(null);
setPolling(false);
setDone(false);
setError(null);
setCopied(false);
intervalRef.current = 5;
invoke<DeviceAuthorization>("kimi_oauth_start", { region: r })
.then((a) => {
if (!activeRef.current) return;
setAuth(a);
@@ -56,11 +78,10 @@ export function KimiOAuthDialog({ open, onClose }: KimiOAuthDialogProps) {
.catch((e) => {
if (!activeRef.current) return;
setError(e instanceof Error ? e.message : String(e));
// Allow picking the region again after a failed launch.
setStarted(false);
});
return () => {
activeRef.current = false;
};
}, [open]);
};
// Poll the token endpoint while the user authorizes in the browser.
useEffect(() => {
@@ -73,6 +94,7 @@ export function KimiOAuthDialog({ open, onClose }: KimiOAuthDialogProps) {
const res = await invoke<PollStatus>("kimi_oauth_poll", {
deviceCode: auth.device_code,
interval: intervalRef.current,
region,
});
if (cancelled) return;
switch (res.status) {
@@ -119,22 +141,8 @@ export function KimiOAuthDialog({ open, onClose }: KimiOAuthDialogProps) {
}, [open, polling, auth]);
const restart = () => {
setAuth(null);
setPolling(false);
setDone(false);
setError(null);
intervalRef.current = 5;
invoke<DeviceAuthorization>("kimi_oauth_start")
.then((a) => {
if (!activeRef.current) return;
setAuth(a);
if (a.interval && a.interval > 0) intervalRef.current = a.interval;
setPolling(true);
})
.catch((e) => {
if (!activeRef.current) return;
setError(e instanceof Error ? e.message : String(e));
});
// Restart always resets to the default region (mainland China).
start("cn");
};
const copyCode = () => {
@@ -214,13 +222,56 @@ export function KimiOAuthDialog({ open, onClose }: KimiOAuthDialogProps) {
<p className="text-sm text-content-muted text-center">
{t("kimiOAuthWaiting")}
</p>
<p className="text-xs text-content-muted text-center">
{region === "global"
? t("kimiOAuthRegionGlobal")
: t("kimiOAuthRegionCn")}
</p>
</>
)}
{!auth && !done && (
{started && !auth && !done && (
<div className="h-3.5 w-2/3 rounded bg-hover-2 animate-pulse mx-auto" />
)}
{!started && !done && (
<div className="space-y-3">
<p className="text-sm text-content-muted">{t("kimiOAuthRegionLabel")}</p>
<div className="grid grid-cols-2 gap-2">
<button
type="button"
onClick={() => setRegion("cn")}
className={`px-3 py-2 text-sm rounded border transition-colors ${
region === "cn"
? "border-blue-600 bg-blue-600/10 text-blue-600 dark:text-blue-400"
: "border-border hover:bg-hover-2 text-content-muted"
}`}
>
{t("kimiOAuthRegionCn")}
</button>
<button
type="button"
onClick={() => setRegion("global")}
className={`px-3 py-2 text-sm rounded border transition-colors ${
region === "global"
? "border-blue-600 bg-blue-600/10 text-blue-600 dark:text-blue-400"
: "border-border hover:bg-hover-2 text-content-muted"
}`}
>
{t("kimiOAuthRegionGlobal")}
</button>
</div>
<button
type="button"
onClick={() => start(region)}
className="w-full px-3 py-2 text-sm rounded bg-blue-600 text-white hover:bg-blue-500 transition-colors"
>
{t("kimiOAuthStart")}
</button>
</div>
)}
<div className="flex items-center justify-end gap-2 pt-1">
{error && !done && (
<button
+9
View File
@@ -54,6 +54,8 @@ function defaultBaseUrl(agent: Agent, type: ProviderType): string {
case "anthropic":
case "vertexai":
return "";
default:
return "";
}
}
// Pi defaults
@@ -68,6 +70,8 @@ function defaultBaseUrl(agent: Agent, type: ProviderType): string {
case "anthropic":
case "vertexai":
return "";
default:
return "";
}
}
@@ -307,6 +311,11 @@ export function ProviderEdit({
{t}
</option>
))}
{!PROVIDER_TYPES.includes(provider.provider_type) && (
<option value={provider.provider_type}>
{t("apiFormatUnknown", { type: provider.provider_type })}
</option>
)}
</select>
</div>
</div>
+239 -199
View File
@@ -4,6 +4,7 @@ import { Pencil, Copy, Activity, Loader2, Trash2, BarChart3 } from "lucide-react
import { useTranslation } from "../i18n";
import { ProviderIcon } from "./ProviderIcon";
import { UsageFooter } from "./UsageFooter";
import { useUsageQuery } from "../hooks/useUsageQuery";
import type { Agent, Model, Provider } from "../types";
interface ConnectivityResult {
@@ -32,6 +33,228 @@ interface ProviderListProps {
agent: Agent;
}
interface ProviderCardProps {
provider: Provider;
agent: Agent;
defaultModel: string | null;
models: Record<string, Model>;
/** Inline connectivity-test state for this provider, or undefined when idle. */
ts: TestState | undefined;
onEdit: (name: string) => void;
onDelete: (name: string) => void;
onDuplicate: (name: string) => void;
onSwitchProvider: (name: string) => void;
onConfigureUsage: (name: string) => void;
onTest: (provider: Provider) => void;
}
function ProviderCard({
provider,
agent,
defaultModel,
models,
ts,
onEdit,
onDelete,
onDuplicate,
onSwitchProvider,
onConfigureUsage,
onTest,
}: ProviderCardProps) {
const { t } = useTranslation();
// Usage query state lives once per card; both the compact (card header) and
// detail (footer) UsageFooter variants read this same state, so a refresh
// from either side updates both.
const usage = useUsageQuery(
agent,
provider.name,
provider.usageKinds,
provider.usageConfig?.autoQueryIntervalMinutes
);
const providerModels = Object.values(models).filter(
(m) => m.provider === provider.name
);
const defaultModelName = defaultModel
? models[defaultModel]?.model || models[defaultModel]?.display_name || defaultModel
: null;
const isActive = provider.active === true;
return (
<div
className={`group relative flex flex-col gap-3 p-4 rounded-xl border transition-colors cursor-pointer w-full ${
isActive
? "bg-green-50 dark:bg-green-900/10 border-green-300 dark:border-green-500/30 hover:border-green-400 dark:border-green-500/50 hover:bg-green-100 dark:bg-green-900/20"
: "bg-panel border-border hover:border-strong hover:bg-hover"
}`}
onClick={() => onEdit(provider.name)}
>
<div className="flex items-center gap-4 w-full">
<ProviderIcon
name={provider.name}
icon={provider.icon}
color={provider.icon_color}
size={44}
/>
<div className="flex-1 min-w-0">
<div className="flex items-center gap-2">
<h3 className="font-semibold text-content-primary truncate">
{provider.name}
</h3>
{isActive && (
<span className="text-xs px-2 py-0.5 rounded-full bg-green-100 dark:bg-green-900/30 text-green-600 dark:text-green-400 border border-green-300 dark:border-green-500/30">
{t("inUse")}
</span>
)}
{provider.note && (
<span className="text-xs text-content-muted truncate max-w-[200px]">
{provider.note}
</span>
)}
</div>
<div className="mt-1 flex items-center gap-3 text-sm text-content-muted flex-wrap">
<span className="font-mono text-xs">
{provider.official_url || provider.base_url || t("noUrl")}
</span>
<span className="text-xs px-2 py-0.5 rounded-full bg-hover-2 text-content-muted border border-border">
{provider.provider_type}
</span>
<span className="text-xs">
{t("modelCount", { count: providerModels.length })}
</span>
</div>
</div>
<div className="flex items-center flex-wrap justify-end gap-2">
{defaultModel &&
models[defaultModel]?.provider === provider.name && (
<span className="text-xs px-2 py-1 rounded-full bg-green-100 dark:bg-green-900/30 text-green-600 dark:text-green-400 border border-green-300 dark:border-green-500/20">
{t("defaultModel", { name: defaultModelName ?? "" })}
</span>
)}
{/* inline connectivity test result */}
{ts && ts.status !== "testing" && (
<span
className={`text-xs px-2 py-0.5 rounded-full border tabular-nums ${
ts.status === "ok"
? ts.latency && ts.latency > 6000
? "bg-orange-100 dark:bg-orange-900/30 text-orange-600 dark:text-orange-400 border-orange-300 dark:border-orange-500/30"
: "bg-green-100 dark:bg-green-900/30 text-green-600 dark:text-green-400 border-green-300 dark:border-green-500/30"
: "bg-red-100 dark:bg-red-900/30 text-red-500 dark:text-red-400 border-red-300 dark:border-red-500/30"
}`}
title={
ts.status === "fail"
? ts.error || t("connectivityFail", { name: provider.name, error: "" })
: ts.latency && ts.latency > 6000
? t("connectivitySlow", { name: provider.name, latency: ts.latency ?? 0 })
: t("connectivityOk", { name: provider.name, latency: ts.latency ?? 0 })
}
>
{ts.status === "ok" ? `${ts.latency}ms` : "✕"}
</span>
)}
{/* compact usage summary — sits left of the switch button,
mirroring cc-switch's card layout (usage → action buttons) */}
{(provider.usageKinds?.length ?? 0) > 0 && (
<UsageFooter usage={usage} variant="compact" />
)}
<button
type="button"
onClick={(e) => {
e.stopPropagation();
onSwitchProvider(provider.name);
}}
className={`px-3 py-1.5 text-sm rounded focus:ring-2 focus:outline-none ${
isActive
? "bg-green-600 hover:bg-green-700 text-white focus:ring-green-500"
: "bg-blue-600 hover:bg-blue-700 text-white focus:ring-blue-500"
}`}
>
{isActive ? t("inUse") : t("switchTo")}
</button>
{agent === "kimi_code" && (
<span
className="text-sm text-content-muted hover:text-content-primary cursor-help select-none"
title={t("switchReloadHint")}
aria-label={t("switchReloadHint")}
>
ⓘ
</span>
)}
{/* icon button group */}
<button
type="button"
onClick={(e) => {
e.stopPropagation();
onEdit(provider.name);
}}
title={t("edit")}
className={iconBtn}
aria-label={t("edit")}
>
<Pencil className="w-4 h-4" />
</button>
<button
type="button"
onClick={(e) => {
e.stopPropagation();
onDuplicate(provider.name);
}}
title={t("copyProvider")}
className={iconBtn}
aria-label={t("copyProvider")}
>
<Copy className="w-4 h-4" />
</button>
<button
type="button"
onClick={(e) => {
e.stopPropagation();
onTest(provider);
}}
disabled={ts?.status === "testing"}
title={t("testConnectivity")}
className={`${iconBtn} disabled:opacity-50`}
aria-label={t("testConnectivity")}
>
{ts?.status === "testing" ? (
<Loader2 className="w-4 h-4 animate-spin" />
) : (
<Activity className="w-4 h-4" />
)}
</button>
<button
type="button"
onClick={(e) => {
e.stopPropagation();
onConfigureUsage(provider.name);
}}
title={t("usageConfigBtn")}
className={iconBtn}
aria-label={t("usageConfigBtn")}
>
<BarChart3 className="w-4 h-4" />
</button>
<button
type="button"
onClick={(e) => {
e.stopPropagation();
onDelete(provider.name);
}}
title={t("delete")}
className={`${iconBtn} hover:text-red-400 hover:border-red-500/30 hover:bg-red-900/20`}
aria-label={t("delete")}
>
<Trash2 className="w-4 h-4" />
</button>
</div>
</div>
<UsageFooter usage={usage} variant="detail" />
</div>
);
}
const iconBtn =
"w-8 h-8 flex items-center justify-center rounded border border-border text-content-muted hover:text-content-primary hover:bg-hover-2 focus:ring-2 focus:ring-blue-500 focus:outline-none transition-colors";
@@ -139,205 +362,22 @@ export function ProviderList({
</div>
) : (
<div className="grid grid-cols-1 gap-3 w-full">
{sortedProviders.map((provider) => {
const providerModels = Object.values(models).filter(
(m) => m.provider === provider.name
);
const defaultModelName = defaultModel
? models[defaultModel]?.model || models[defaultModel]?.display_name || defaultModel
: null;
const isActive = provider.active === true;
const ts = testState[provider.name];
return (
<div
key={provider.name}
className={`group relative flex flex-col gap-3 p-4 rounded-xl border transition-colors cursor-pointer w-full ${
isActive
? "bg-green-50 dark:bg-green-900/10 border-green-300 dark:border-green-500/30 hover:border-green-400 dark:border-green-500/50 hover:bg-green-100 dark:bg-green-900/20"
: "bg-panel border-border hover:border-strong hover:bg-hover"
}`}
onClick={() => onEdit(provider.name)}
>
<div className="flex items-center gap-4 w-full">
<ProviderIcon
name={provider.name}
icon={provider.icon}
color={provider.icon_color}
size={44}
/>
<div className="flex-1 min-w-0">
<div className="flex items-center gap-2">
<h3 className="font-semibold text-content-primary truncate">
{provider.name}
</h3>
{isActive && (
<span className="text-xs px-2 py-0.5 rounded-full bg-green-100 dark:bg-green-900/30 text-green-600 dark:text-green-400 border border-green-300 dark:border-green-500/30">
{t("inUse")}
</span>
)}
{provider.note && (
<span className="text-xs text-content-muted truncate max-w-[200px]">
{provider.note}
</span>
)}
</div>
<div className="mt-1 flex items-center gap-3 text-sm text-content-muted flex-wrap">
<span className="font-mono text-xs">
{provider.official_url || provider.base_url || t("noUrl")}
</span>
<span className="text-xs px-2 py-0.5 rounded-full bg-hover-2 text-content-muted border border-border">
{provider.provider_type}
</span>
<span className="text-xs">
{t("modelCount", { count: providerModels.length })}
</span>
</div>
</div>
<div className="flex items-center flex-wrap justify-end gap-2">
{defaultModel &&
models[defaultModel]?.provider === provider.name && (
<span className="text-xs px-2 py-1 rounded-full bg-green-100 dark:bg-green-900/30 text-green-600 dark:text-green-400 border border-green-300 dark:border-green-500/20">
{t("defaultModel", { name: defaultModelName ?? "" })}
</span>
)}
{/* inline connectivity test result */}
{ts && ts.status !== "testing" && (
<span
className={`text-xs px-2 py-0.5 rounded-full border tabular-nums ${
ts.status === "ok"
? ts.latency && ts.latency > 6000
? "bg-orange-100 dark:bg-orange-900/30 text-orange-600 dark:text-orange-400 border-orange-300 dark:border-orange-500/30"
: "bg-green-100 dark:bg-green-900/30 text-green-600 dark:text-green-400 border-green-300 dark:border-green-500/30"
: "bg-red-100 dark:bg-red-900/30 text-red-500 dark:text-red-400 border-red-300 dark:border-red-500/30"
}`}
title={
ts.status === "fail"
? ts.error || t("connectivityFail", { name: provider.name, error: "" })
: ts.latency && ts.latency > 6000
? t("connectivitySlow", { name: provider.name, latency: ts.latency ?? 0 })
: t("connectivityOk", { name: provider.name, latency: ts.latency ?? 0 })
}
>
{ts.status === "ok" ? `${ts.latency}ms` : "✕"}
</span>
)}
{/* compact usage summary — sits left of the switch button,
mirroring cc-switch's card layout (usage → action buttons) */}
{(provider.usageKinds?.length ?? 0) > 0 && (
<UsageFooter
agent={agent}
providerName={provider.name}
usageKinds={provider.usageKinds}
variant="compact"
autoIntervalMinutes={
provider.usageConfig?.autoQueryIntervalMinutes
}
/>
)}
<button
type="button"
onClick={(e) => {
e.stopPropagation();
onSwitchProvider(provider.name);
}}
className={`px-3 py-1.5 text-sm rounded focus:ring-2 focus:outline-none ${
isActive
? "bg-green-600 hover:bg-green-700 text-white focus:ring-green-500"
: "bg-blue-600 hover:bg-blue-700 text-white focus:ring-blue-500"
}`}
>
{isActive ? t("inUse") : t("switchTo")}
</button>
{agent === "kimi_code" && (
<span
className="text-sm text-content-muted hover:text-content-primary cursor-help select-none"
title={t("switchReloadHint")}
aria-label={t("switchReloadHint")}
>
ⓘ
</span>
)}
{/* icon button group */}
<button
type="button"
onClick={(e) => {
e.stopPropagation();
onEdit(provider.name);
}}
title={t("edit")}
className={iconBtn}
aria-label={t("edit")}
>
<Pencil className="w-4 h-4" />
</button>
<button
type="button"
onClick={(e) => {
e.stopPropagation();
onDuplicate(provider.name);
}}
title={t("copyProvider")}
className={iconBtn}
aria-label={t("copyProvider")}
>
<Copy className="w-4 h-4" />
</button>
<button
type="button"
onClick={(e) => {
e.stopPropagation();
handleTest(provider);
}}
disabled={ts?.status === "testing"}
title={t("testConnectivity")}
className={`${iconBtn} disabled:opacity-50`}
aria-label={t("testConnectivity")}
>
{ts?.status === "testing" ? (
<Loader2 className="w-4 h-4 animate-spin" />
) : (
<Activity className="w-4 h-4" />
)}
</button>
<button
type="button"
onClick={(e) => {
e.stopPropagation();
onConfigureUsage(provider.name);
}}
title={t("usageConfigBtn")}
className={iconBtn}
aria-label={t("usageConfigBtn")}
>
<BarChart3 className="w-4 h-4" />
</button>
<button
type="button"
onClick={(e) => {
e.stopPropagation();
onDelete(provider.name);
}}
title={t("delete")}
className={`${iconBtn} hover:text-red-400 hover:border-red-500/30 hover:bg-red-900/20`}
aria-label={t("delete")}
>
<Trash2 className="w-4 h-4" />
</button>
</div>
</div>
<UsageFooter
agent={agent}
providerName={provider.name}
usageKinds={provider.usageKinds}
variant="detail"
/>
</div>
);
})}
{sortedProviders.map((provider) => (
<ProviderCard
key={provider.name}
provider={provider}
agent={agent}
defaultModel={defaultModel}
models={models}
ts={testState[provider.name]}
onEdit={onEdit}
onDelete={onDelete}
onDuplicate={onDuplicate}
onSwitchProvider={onSwitchProvider}
onConfigureUsage={onConfigureUsage}
onTest={handleTest}
/>
))}
</div>
)}
</div>
+86 -24
View File
@@ -9,6 +9,7 @@ import {
forcedEnvValue,
getExperimentalFlags,
getSubagentModelPool,
isExperimentalFlagSet,
isFlagLockedByEnv,
isMasterEnvOn,
removeSubagentPoolEntry,
@@ -33,22 +34,31 @@ interface SubagentSettingsPageProps {
onBack: () => void;
}
const EFFORTS = ["low", "medium", "high", "max"] as const;
// Upstream removed the "max" effort tier (auto-migrates to "high").
const EFFORTS = ["low", "medium", "high"] as const;
const EFFORT_LABELS: Record<(typeof EFFORTS)[number], TranslationKey> = {
low: "thinkingLow",
medium: "thinkingMedium",
high: "thinkingHigh",
max: "thinkingMax",
};
const FLAG_LABELS: Record<string, { name: TranslationKey; desc: TranslationKey }> = {
"secondary-model": { name: "flagSecondaryModel", desc: "flagSecondaryModelDesc" },
"tool-select": { name: "flagToolSelect", desc: "flagToolSelectDesc" },
"acp-v2": { name: "flagAcpV2", desc: "flagAcpV2Desc" },
persistence_minidb_readmodel: {
name: "flagMinidbReadmodel",
desc: "flagMinidbReadmodelDesc",
},
tower: { name: "flagTower", desc: "flagTowerDesc" },
subagent_fork: { name: "flagSubagentFork", desc: "flagSubagentForkDesc" },
wait_for: { name: "flagWaitFor", desc: "flagWaitForDesc" },
auto_session_title: {
name: "flagAutoSessionTitle",
desc: "flagAutoSessionTitleDesc",
},
"remote-control": { name: "flagRemoteControl", desc: "flagRemoteControlDesc" },
search_worker: { name: "flagSearchWorker", desc: "flagSearchWorkerDesc" },
file_history: { name: "flagFileHistory", desc: "flagFileHistoryDesc" },
};
/** Validation-error i18n key per engine rule, for the pre-write self-check. */
@@ -154,6 +164,8 @@ export function SubagentSettingsPage({
const [poolErrors, setPoolErrors] = useState<PoolValidationError[]>([]);
/** Local draft for the "add pool entry" select (reset after each pick). */
const [addSelection, setAddSelection] = useState("");
/** WebUI-open button in flight; disables both buttons while non-null. */
const [webuiBusy, setWebuiBusy] = useState<"embedded" | "browser" | null>(null);
useEffect(() => {
invoke<ExperimentalEnvStatus>("get_experimental_env_status")
@@ -177,13 +189,18 @@ export function SubagentSettingsPage({
const secondaryFlag = EXPERIMENTAL_FLAGS[0]; // "secondary-model"
const otherFlags = EXPERIMENTAL_FLAGS.slice(1);
/** Effective state of the secondary-model flag (env overrides config). */
const secondaryEnabled = masterOn
? true
: isFlagLockedByEnv(env, secondaryFlag)
? forcedEnvValue(env, secondaryFlag)
: flags["secondary-model"] === true;
const secondaryLocked = masterOn || isFlagLockedByEnv(env, secondaryFlag);
/** Effective state of the secondary-model flag. Mirrors the kimi-code
* 0.40.1 priority: single-flag env > explicit [experimental] value >
* master env (force-on only) > upstream default. The master env no
* longer locks the toggle — only the flag's own env var does. */
const secondaryEnabled = isFlagLockedByEnv(env, secondaryFlag)
? forcedEnvValue(env, secondaryFlag)
: isExperimentalFlagSet(rawOther, secondaryFlag.id)
? flags["secondary-model"] === true
: masterOn
? true
: (secondaryFlag.defaultEnabled ?? false);
const secondaryLocked = isFlagLockedByEnv(env, secondaryFlag);
const aliasList = Object.keys(models).sort();
@@ -229,7 +246,9 @@ export function SubagentSettingsPage({
? `${Math.round(n / 1000)}K`
: String(n);
const effortLabel = (e: string): string => {
const key = EFFORT_LABELS[e as (typeof EFFORTS)[number]];
// Stored "max" tiers from old configs are shown as "high" (upstream
// removed the tier; it auto-migrates to "high").
const key = EFFORT_LABELS[e === "max" ? "high" : (e as (typeof EFFORTS)[number])];
return key ? t(key) : e;
};
@@ -290,16 +309,35 @@ export function SubagentSettingsPage({
const renderFlagRow = (flag: ExperimentalFlagDef) => {
const labels = FLAG_LABELS[flag.id];
const locked = masterOn || isFlagLockedByEnv(env, flag);
const on = masterOn
? true
: isFlagLockedByEnv(env, flag)
? forcedEnvValue(env, flag)
: flags[flag.id] === true;
// Only the flag's own env var locks the toggle. The master env force-ons
// undefined flags but an explicit config entry outranks it, so the user
// can still flip values here while it is set.
const locked = isFlagLockedByEnv(env, flag);
// Resolution order mirrors kimi-code 0.40.1 flagService:
// single-flag env > explicit [experimental] value (true *or* false) >
// master env (on-only) > upstream default (`defaultEnabled`).
const explicitlySet = isExperimentalFlagSet(rawOther, flag.id);
const on = locked
? forcedEnvValue(env, flag)
: explicitlySet
? flags[flag.id] === true
: masterOn
? true
: (flag.defaultEnabled ?? false);
// Turning the flag off only sticks via an explicit `false` when the
// fallback (master env or the upstream default) would otherwise keep it on.
const explicitFalse = masterOn || flag.defaultEnabled === true;
return (
<div key={flag.id} className="flex items-center gap-3">
<div className="flex-1 min-w-0">
<div className="text-sm text-content-primary">{t(labels.name)}</div>
<div className="flex items-center gap-2 text-sm text-content-primary">
{t(labels.name)}
{!locked && !explicitlySet && flag.defaultEnabled && (
<span className="shrink-0 text-xs text-blue-600 dark:text-blue-400 border border-blue-500/30 rounded px-1">
{t("flagDefaultOn")}
</span>
)}
</div>
<div className="text-xs text-content-muted">
{t(labels.desc)}
<code className="ml-2">{flag.envVar}</code>
@@ -315,7 +353,9 @@ export function SubagentSettingsPage({
disabled={locked}
ariaLabel={t(labels.name)}
onChange={(checked) =>
onChange(setExperimentalFlag(rawOther, flag.id, checked))
onChange(
setExperimentalFlag(rawOther, flag.id, checked, { explicitFalse })
)
}
/>
</div>
@@ -349,29 +389,37 @@ export function SubagentSettingsPage({
<div className="mt-3 flex flex-wrap gap-2">
<button
type="button"
disabled={webuiBusy !== null}
onClick={async () => {
setWebuiBusy("embedded");
try {
await invoke("open_kimi_web_embedded");
} catch (err) {
alert(err instanceof Error ? err.message : String(err));
} finally {
setWebuiBusy(null);
}
}}
className="px-3 py-1.5 text-sm rounded bg-blue-600 text-white hover:bg-blue-500 focus:ring-2 focus:ring-blue-500 focus:outline-none"
className="px-3 py-1.5 text-sm rounded bg-blue-600 text-white hover:bg-blue-500 focus:ring-2 focus:ring-blue-500 focus:outline-none disabled:opacity-50 disabled:cursor-not-allowed"
>
{t("openWebUIEmbedded")}
{webuiBusy === "embedded" ? t("webuiOpening") : t("openWebUIEmbedded")}
</button>
<button
type="button"
disabled={webuiBusy !== null}
onClick={async () => {
setWebuiBusy("browser");
try {
await invoke("open_kimi_web");
} catch (err) {
alert(err instanceof Error ? err.message : String(err));
} finally {
setWebuiBusy(null);
}
}}
className="px-3 py-1.5 text-sm border border-border rounded hover:bg-hover-2 focus:ring-2 focus:ring-blue-500 focus:outline-none"
className="px-3 py-1.5 text-sm border border-border rounded hover:bg-hover-2 focus:ring-2 focus:ring-blue-500 focus:outline-none disabled:opacity-50 disabled:cursor-not-allowed"
>
{t("openWebUIBrowser")}
{webuiBusy === "browser" ? t("webuiOpening") : t("openWebUIBrowser")}
</button>
</div>
</Card>
@@ -528,6 +576,16 @@ export function SubagentSettingsPage({
<div className="border-t border-border" />
<div className="flex items-center gap-3">
<div className="flex-1 min-w-0">
<div className="flex items-center gap-2 text-sm text-content-primary">
{t(FLAG_LABELS[secondaryFlag.id].name)}
{!secondaryLocked &&
!isExperimentalFlagSet(rawOther, secondaryFlag.id) &&
secondaryFlag.defaultEnabled && (
<span className="shrink-0 text-xs text-blue-600 dark:text-blue-400 border border-blue-500/30 rounded px-1">
{t("flagDefaultOn")}
</span>
)}
</div>
<div className="text-xs text-content-muted">
{t(FLAG_LABELS[secondaryFlag.id].desc)}
<code className="ml-2">{secondaryFlag.envVar}</code>
@@ -543,7 +601,11 @@ export function SubagentSettingsPage({
disabled={secondaryLocked}
ariaLabel={t(FLAG_LABELS[secondaryFlag.id].name)}
onChange={(checked) =>
onChange(setExperimentalFlag(rawOther, secondaryFlag.id, checked))
onChange(
setExperimentalFlag(rawOther, secondaryFlag.id, checked, {
explicitFalse: masterOn || secondaryFlag.defaultEnabled === true,
})
)
}
/>
</div>
+10 -162
View File
@@ -1,175 +1,23 @@
import { useCallback, useEffect, useRef, useState } from "react";
import { invoke } from "@tauri-apps/api/core";
import { useEffect, useState } from "react";
import { Loader2, RefreshCw } from "lucide-react";
import { useTranslation } from "../i18n";
import { localizeUsageError, planLabel } from "../lib/usage-display";
import type { Agent } from "../types";
interface UsageData {
planName?: string | null;
remaining?: number | null;
total?: number | null;
used?: number | null;
unit?: string | null;
isValid?: boolean | null;
resetsAt?: string | null;
}
interface UsageResult {
success: boolean;
data?: UsageData[] | null;
error?: string | null;
}
type UsageStatus = "idle" | "loading" | "success" | "error";
interface CacheEntry {
status: "success" | "error";
data: UsageData[];
/** Raw error text from Rust; null = transient failure (invoke rejected). */
error: string | null;
updatedAt: number;
}
// Module-level cache shared across mounts: re-entering the list within the
// stale TTL shows the last result without firing new requests. Both the
// compact (card header) and detail (footer) variants read this same cache.
const STALE_TTL_MS = 5 * 60 * 1000;
const cache = new Map<string, CacheEntry>();
// Simple semaphore: at most MAX_CONCURRENT queries in flight at once.
const MAX_CONCURRENT = 3;
let running = 0;
const waiters: Array<() => void> = [];
async function acquireSlot(): Promise<void> {
if (running >= MAX_CONCURRENT) {
await new Promise<void>((resolve) => waiters.push(resolve));
}
running += 1;
}
function releaseSlot(): void {
running -= 1;
waiters.shift()?.();
}
import type { UsageData, UsageQueryState } from "../hooks/useUsageQuery";
interface UsageFooterProps {
agent: Agent;
providerName: string;
usageKinds?: string[];
/** Query state lifted to the provider card via useUsageQuery. Both the
* compact (card header) and detail (footer) variants read the same state,
* so a refresh from either updates both. */
usage: UsageQueryState;
/** "detail" (default) renders the multi-line footer; "compact" renders a
* one-line summary + last-updated + refresh button for the card header. */
variant?: "detail" | "compact";
/** Auto query interval in minutes; only wired on the compact variant so
* both variants do not double-fire. 0/undefined = manual only. */
autoIntervalMinutes?: number;
}
export function UsageFooter({
agent,
providerName,
usageKinds,
variant = "detail",
autoIntervalMinutes,
}: UsageFooterProps) {
export function UsageFooter({ usage, variant = "detail" }: UsageFooterProps) {
const { t } = useTranslation();
const supported = (usageKinds?.length ?? 0) > 0;
// Cache key includes the agent so a Kimi Code provider and a Pi provider
// with the same name do not clobber each other's cached result.
const cacheKey = `${agent}:${providerName}`;
const [status, setStatus] = useState<UsageStatus>("idle");
const [data, setData] = useState<UsageData[]>([]);
/** undefined = no error; null = network error; string = Rust error text. */
const [error, setError] = useState<string | null | undefined>(undefined);
const [updatedAt, setUpdatedAt] = useState<number | null>(null);
const { status, data, error, updatedAt, supported, refresh } = usage;
const [now, setNow] = useState(() => Date.now());
// Generation counter: stale responses (unmounted / superseded query) are ignored.
const genRef = useRef(0);
const runQuery = useCallback(
async (forceRefresh: boolean) => {
const gen = ++genRef.current;
setStatus("loading");
setError(undefined);
const finish = (entry: CacheEntry) => {
cache.set(cacheKey, entry);
if (genRef.current !== gen) return;
setStatus(entry.status);
setData(entry.data);
setError(entry.error);
setUpdatedAt(entry.updatedAt);
};
try {
await acquireSlot();
let result: UsageResult;
try {
result = await invoke<UsageResult>("query_provider_usage", {
agent,
providerName,
forceRefresh,
});
} finally {
releaseSlot();
}
if (genRef.current !== gen) return;
if (result.success) {
finish({
status: "success",
data: result.data ?? [],
error: null,
updatedAt: Date.now(),
});
} else {
// Deterministic failure: keep last good data for ghost display.
finish({
status: "error",
data: cache.get(cacheKey)?.data ?? [],
error: result.error ?? "",
updatedAt: Date.now(),
});
}
} catch {
// Transient failure (network / timeout): invoke rejected.
finish({
status: "error",
data: cache.get(cacheKey)?.data ?? [],
error: null,
updatedAt: Date.now(),
});
}
},
[agent, providerName, cacheKey]
);
// On mount / provider change: serve fresh cache, otherwise query once.
useEffect(() => {
if (!supported) return;
const cached = cache.get(cacheKey);
if (cached) {
setStatus(cached.status);
setData(cached.data);
setError(cached.error);
setUpdatedAt(cached.updatedAt);
if (Date.now() - cached.updatedAt < STALE_TTL_MS) return;
}
void runQuery(false);
}, [supported, cacheKey, runQuery]);
// Ignore late responses after unmount.
useEffect(() => {
return () => {
genRef.current += 1;
};
}, []);
// Auto query interval (compact variant only, to avoid double-firing).
useEffect(() => {
if (variant !== "compact" || !supported) return;
const mins = autoIntervalMinutes ?? 0;
if (mins <= 0) return;
const id = setInterval(() => void runQuery(false), mins * 60_000);
return () => clearInterval(id);
}, [variant, supported, autoIntervalMinutes, runQuery]);
// Tick relative times once a minute while showing data.
useEffect(() => {
@@ -226,7 +74,7 @@ export function UsageFooter({
type="button"
onClick={(e) => {
e.stopPropagation();
void runQuery(true);
void refresh(true);
}}
disabled={status === "loading"}
title={t("usageRefresh")}
@@ -344,7 +192,7 @@ export function UsageFooter({
type="button"
onClick={(e) => {
e.stopPropagation();
void runQuery(true);
void refresh(true);
}}
className="ml-auto shrink-0 px-2 py-0.5 rounded border border-red-300 dark:border-red-500/30 text-red-500 dark:text-red-400 hover:bg-red-50 dark:hover:bg-red-900/20 transition-colors"
>
+174
View File
@@ -0,0 +1,174 @@
import { useCallback, useEffect, useRef, useState } from "react";
import { invoke } from "@tauri-apps/api/core";
import type { Agent } from "../types";
export interface UsageData {
planName?: string | null;
remaining?: number | null;
total?: number | null;
used?: number | null;
unit?: string | null;
isValid?: boolean | null;
resetsAt?: string | null;
}
export interface UsageResult {
success: boolean;
data?: UsageData[] | null;
error?: string | null;
}
export type UsageStatus = "idle" | "loading" | "success" | "error";
export interface CacheEntry {
status: "success" | "error";
data: UsageData[];
/** Raw error text from Rust; null = transient failure (invoke rejected). */
error: string | null;
updatedAt: number;
}
// Module-level cache shared across mounts: re-entering the list within the
// stale TTL shows the last result without firing new requests. Both the
// compact (card header) and detail (footer) variants read this same cache.
const STALE_TTL_MS = 5 * 60 * 1000;
const cache = new Map<string, CacheEntry>();
// Simple semaphore: at most MAX_CONCURRENT queries in flight at once.
const MAX_CONCURRENT = 3;
let running = 0;
const waiters: Array<() => void> = [];
async function acquireSlot(): Promise<void> {
if (running >= MAX_CONCURRENT) {
await new Promise<void>((resolve) => waiters.push(resolve));
}
running += 1;
}
function releaseSlot(): void {
running -= 1;
waiters.shift()?.();
}
export interface UsageQueryState {
status: UsageStatus;
data: UsageData[];
error: string | null | undefined;
updatedAt: number | null;
refresh: (force: boolean) => void;
supported: boolean;
}
export function useUsageQuery(
agent: Agent,
providerName: string,
usageKinds?: string[],
autoIntervalMinutes?: number
): UsageQueryState {
const supported = (usageKinds?.length ?? 0) > 0;
// Cache key includes the agent so a Kimi Code provider and a Pi provider
// with the same name do not clobber each other's cached result.
const cacheKey = `${agent}:${providerName}`;
const [status, setStatus] = useState<UsageStatus>("idle");
const [data, setData] = useState<UsageData[]>([]);
/** undefined = no error; null = network error; string = Rust error text. */
const [error, setError] = useState<string | null | undefined>(undefined);
const [updatedAt, setUpdatedAt] = useState<number | null>(null);
// Generation counter: stale responses (unmounted / superseded query) are ignored.
const genRef = useRef(0);
const runQuery = useCallback(
async (forceRefresh: boolean) => {
const gen = ++genRef.current;
setStatus("loading");
setError(undefined);
const finish = (entry: CacheEntry) => {
cache.set(cacheKey, entry);
if (genRef.current !== gen) return;
setStatus(entry.status);
setData(entry.data);
setError(entry.error);
setUpdatedAt(entry.updatedAt);
};
try {
await acquireSlot();
let result: UsageResult;
try {
result = await invoke<UsageResult>("query_provider_usage", {
agent,
providerName,
forceRefresh,
});
} finally {
releaseSlot();
}
if (genRef.current !== gen) return;
if (result.success) {
finish({
status: "success",
data: result.data ?? [],
error: null,
updatedAt: Date.now(),
});
} else {
// Deterministic failure: keep last good data for ghost display.
finish({
status: "error",
data: cache.get(cacheKey)?.data ?? [],
error: result.error ?? "",
updatedAt: Date.now(),
});
}
} catch {
// Transient failure (network / timeout): invoke rejected.
finish({
status: "error",
data: cache.get(cacheKey)?.data ?? [],
error: null,
updatedAt: Date.now(),
});
}
},
[agent, providerName, cacheKey]
);
// On mount / provider change: serve fresh cache, otherwise query once.
useEffect(() => {
if (!supported) return;
const cached = cache.get(cacheKey);
if (cached) {
setStatus(cached.status);
setData(cached.data);
setError(cached.error);
setUpdatedAt(cached.updatedAt);
if (Date.now() - cached.updatedAt < STALE_TTL_MS) return;
}
void runQuery(false);
}, [supported, cacheKey, runQuery]);
// Ignore late responses after unmount.
useEffect(() => {
return () => {
genRef.current += 1;
};
}, []);
// Auto query interval — the hook is called once per provider card and both
// variants read the same state, so there is no second mount to double-fire.
useEffect(() => {
if (!supported) return;
const mins = autoIntervalMinutes ?? 0;
if (mins <= 0) return;
const id = setInterval(() => void runQuery(false), mins * 60_000);
return () => clearInterval(id);
}, [supported, autoIntervalMinutes, runQuery]);
return {
status,
data,
error,
updatedAt,
refresh: runQuery,
supported,
};
}
+27 -4
View File
@@ -68,8 +68,13 @@ export const enTranslations: Record<TranslationKey, string> = {
kimiOAuthRetry: "Restart",
kimiOAuthCancel: "Cancel",
kimiOAuthNetworkError: "Network error, retrying…",
kimiOAuthRegionLabel: "Sign-in region",
kimiOAuthRegionCn: "Mainland China (auth.kimi.com)",
kimiOAuthRegionGlobal: "International (auth.kimi.ai)",
kimiOAuthStart: "Start sign-in",
apiSettings: "API Settings",
apiFormat: "API Format",
apiFormatUnknown: "Unknown format ({type}, kept verbatim)",
authField: "Auth Field",
apiKey: "API Key",
getApiKeyLink: "Get API Key",
@@ -133,7 +138,6 @@ export const enTranslations: Record<TranslationKey, string> = {
thinkingLow: "Low",
thinkingMedium: "Medium",
thinkingHigh: "High",
thinkingMax: "Max",
thinkingContextHint: "Thinking uses more context. Ensure the model context length and reserved size are sufficient.",
loopControlSettings: "Loop Control",
maxAttemptsPerStep: "Max attempts per step",
@@ -147,6 +151,9 @@ export const enTranslations: Record<TranslationKey, string> = {
permissionAllow: "Allow",
permissionDeny: "Deny",
permissionAsk: "Ask",
permissionDangerousGuard: "Dangerous Command Guard",
permissionDangerousGuardDesc:
"When on (default): Auto mode refuses dangerous commands (rm -rf, shutdown, dd of=, ...) and other modes always prompt; turning it off restores the previous behavior. Env KIMI_CODE_DANGEROUS_COMMAND_GUARD overrides this config",
addRule: "+ Add rule",
addCommonRules: "Add common rules",
hooks: "Lifecycle Hooks",
@@ -461,12 +468,27 @@ export const enTranslations: Record<TranslationKey, string> = {
flagSecondaryModelDesc: "Newly spawned subagents bind a second (usually cheaper) model config",
flagToolSelect: "Tool Select",
flagToolSelectDesc: "Enable the experimental tool selection feature",
flagAcpV2: "ACP v2 Protocol",
flagAcpV2Desc: "Enable Agent Communication Protocol v2",
flagMinidbReadmodel: "MiniDB Read Model",
flagMinidbReadmodelDesc: "Enable the v2 engine MiniDB read-model backend",
flagTower: "Tower Mode",
flagTowerDesc: "Enable tower mode: coordinate multiple agents on a shared objective (/tower command)",
flagSubagentFork: "Subagent Fork Context",
flagSubagentForkDesc: "Agent/AgentSwarm tools can start a subagent with a snapshot of the calling agent's history (fork parameter)",
flagWaitFor: "WaitFor Tool",
flagWaitForDesc: "The agent can wait for background tasks to finish within the current turn",
flagAutoSessionTitle: "Auto Session Title",
flagAutoSessionTitleDesc: "Generate session titles automatically via the managed chat_title tool",
flagRemoteControl: "Remote Control",
flagRemoteControlDesc: "Enable the experimental remote control feature",
flagSearchWorker: "Search Worker",
flagSearchWorkerDesc: "Run the kap-server global search backend in a background worker host",
flagFileHistory: "File History",
flagFileHistoryDesc:
"Snapshot edited files before/after each turn (last 5 turns across 30 sessions, stored in the session data dir) for real whole-file diffs",
flagDefaultOn: "On by default",
lockedByEnv: "Locked by env var",
masterEnvOnHint: "KIMI_CODE_EXPERIMENTAL_FLAG is set: all experimental features are forced on by the env var",
masterEnvOnHint:
"KIMI_CODE_EXPERIMENTAL_FLAG is set: flags without an explicit [experimental] entry are forced on; explicit entries in config.toml still win",
secondaryModelSection: "Subagent Model (Secondary Model)",
secondaryModelDisabledHint:
"The experimental flag \"Subagent Secondary Model\" is off and this config will not take effect — enable the toggle above first",
@@ -515,6 +537,7 @@ export const enTranslations: Record<TranslationKey, string> = {
"Open the new Web UI in an independent in-app window, or in your system browser (built into kimi-code 0.33+). Requires the kimi CLI on PATH.",
openWebUIEmbedded: "Open in App",
openWebUIBrowser: "Open in Browser",
webuiOpening: "Opening...",
// Plugin marketplace
pluginMarketplace: "Plugin Marketplace",
+27 -4
View File
@@ -66,8 +66,13 @@ export const zhTranslations = {
kimiOAuthRetry: "重新开始",
kimiOAuthCancel: "取消",
kimiOAuthNetworkError: "网络错误,正在重试…",
kimiOAuthRegionLabel: "登录区域",
kimiOAuthRegionCn: "中国大陆 (auth.kimi.com)",
kimiOAuthRegionGlobal: "国际版 (auth.kimi.ai)",
kimiOAuthStart: "开始登录",
apiSettings: "API 设置",
apiFormat: "API 格式",
apiFormatUnknown: "未知格式({type},原样保留)",
authField: "认证字段",
apiKey: "API Key",
getApiKeyLink: "获取 API Key",
@@ -131,7 +136,6 @@ export const zhTranslations = {
thinkingLow: "低",
thinkingMedium: "中",
thinkingHigh: "高",
thinkingMax: "最大",
thinkingContextHint: "启用思考会占用更多上下文,请确保模型上下文长度和预留空间足够。",
loopControlSettings: "循环控制",
maxAttemptsPerStep: "单步最大尝试次数",
@@ -145,6 +149,9 @@ export const zhTranslations = {
permissionAllow: "允许",
permissionDeny: "拒绝",
permissionAsk: "询问",
permissionDangerousGuard: "危险命令防护",
permissionDangerousGuardDesc:
"开启(默认)时:Auto 模式直接拒绝危险命令(rm -rf、shutdown、dd of= 等),其它模式强制询问;关闭后回归旧行为。环境变量 KIMI_CODE_DANGEROUS_COMMAND_GUARD 会覆盖本配置",
addRule: "+ 添加规则",
addCommonRules: "添加常用规则",
hooks: "生命周期钩子",
@@ -456,12 +463,27 @@ export const zhTranslations = {
flagSecondaryModelDesc: "子代理派发时绑定第二份(通常更便宜的)模型配置",
flagToolSelect: "工具选择",
flagToolSelectDesc: "启用实验性工具选择功能",
flagAcpV2: "ACP v2 协议",
flagAcpV2Desc: "启用 Agent Communication Protocol v2",
flagMinidbReadmodel: "MiniDB 读模型",
flagMinidbReadmodelDesc: "启用 v2 引擎 MiniDB 读模型后端",
flagTower: "Tower 模式",
flagTowerDesc: "启用 Tower 多智能体协同模式(/tower 命令切换)",
flagSubagentFork: "子代理 Fork 上下文",
flagSubagentForkDesc: "Agent/AgentSwarm 工具可携带主代理会话快照启动子代理(fork 参数)",
flagWaitFor: "WaitFor 工具",
flagWaitForDesc: "代理可在当前回合内等待后台任务完成,而无需结束回合再被唤醒",
flagAutoSessionTitle: "自动会话标题",
flagAutoSessionTitleDesc: "通过托管 chat_title 工具自动生成会话标题",
flagRemoteControl: "远程控制",
flagRemoteControlDesc: "启用实验性远程控制功能",
flagSearchWorker: "搜索 Worker",
flagSearchWorkerDesc: "kap-server 全局搜索的后台 worker 宿主服务",
flagFileHistory: "文件历史",
flagFileHistoryDesc:
"记录每轮编辑文件的前后快照(最近 30 个会话×最近 5 轮,存于会话数据目录),用于真实的整文件 diff",
flagDefaultOn: "默认开启",
lockedByEnv: "被环境变量锁定",
masterEnvOnHint: "KIMI_CODE_EXPERIMENTAL_FLAG 已设置:全部实验功能被环境变量强制开启",
masterEnvOnHint:
"KIMI_CODE_EXPERIMENTAL_FLAG 已设置:未显式配置的实验项将被强制开启;config.toml 中的显式配置优先生效",
secondaryModelSection: "子代理模型(次主力模型)",
secondaryModelDisabledHint:
"实验开关「子代理次主力模型」未启用,本配置不会生效——请先在上方打开对应开关",
@@ -507,6 +529,7 @@ export const zhTranslations = {
"以独立窗口在应用内打开新版 Web 界面,也可以选择在系统浏览器打开(kimi-code 0.33+ 内置 code-app;需要 kimi 命令在 PATH 中)。",
openWebUIEmbedded: "在应用内打开",
openWebUIBrowser: "在浏览器打开",
webuiOpening: "打开中...",
// Plugin marketplace
pluginMarketplace: "插件市场",
+206
View File
@@ -0,0 +1,206 @@
import { describe, expect, it } from "vitest";
import { getAgentSettings, setAgentSettings } from "./agent-settings";
// ---------------------------------------------------------------------------
// Helpers — drill into the written `[thinking]` / `[loop_control]` sections
// ---------------------------------------------------------------------------
function thinkingOf(raw: unknown): Record<string, unknown> {
const t = (raw as { thinking?: unknown })?.thinking;
return t && typeof t === "object" && !Array.isArray(t)
? (t as Record<string, unknown>)
: {};
}
function loopOf(raw: unknown): Record<string, unknown> {
const l = (raw as { loop_control?: unknown })?.loop_control;
return l && typeof l === "object" && !Array.isArray(l)
? (l as Record<string, unknown>)
: {};
}
// ---------------------------------------------------------------------------
// Reading — legacy off values normalized to "off", "max" → "high"
// ---------------------------------------------------------------------------
describe("getAgentSettings — thinking.keep normalization", () => {
it("normalizes a legacy boolean `false` to \"off\"", () => {
expect(getAgentSettings({ thinking: { keep: false } }).thinking?.keep).toBe(
"off"
);
});
it("normalizes the other legacy off values (0, null, \"no\", \"none\") to \"off\"", () => {
for (const v of [0, null, "no", "none"]) {
expect(
getAgentSettings({ thinking: { keep: v } }).thinking?.keep
).toBe("off");
}
});
it("keeps \"all\" and \"off\" as-is on read", () => {
expect(getAgentSettings({ thinking: { keep: "all" } }).thinking?.keep).toBe(
"all"
);
expect(getAgentSettings({ thinking: { keep: "off" } }).thinking?.keep).toBe(
"off"
);
});
it("keeps the default \"all\" when the key is absent", () => {
expect(getAgentSettings({}).thinking?.keep).toBe("all");
});
});
describe("getAgentSettings — effort \"max\" read mapping", () => {
it("normalizes a stored \"max\" to \"high\" on read", () => {
expect(getAgentSettings({ thinking: { effort: "max" } }).thinking?.effort).toBe(
"high"
);
});
});
// ---------------------------------------------------------------------------
// Writing — keep: "all" round-trips, "off" is written for legacy off values,
// absent keep is not materialized
// ---------------------------------------------------------------------------
describe("setAgentSettings — keep serialization", () => {
it("round-trips keep = \"all\"", () => {
const raw = { thinking: { keep: "all" } };
const next = setAgentSettings(raw, { thinking: { keep: "all" } });
expect(thinkingOf(next).keep).toBe("all");
});
it("writes \"off\" (string) for a legacy keep = false, never a boolean", () => {
const next = setAgentSettings({ thinking: { keep: false } }, {});
expect(thinkingOf(next).keep).toBe("off");
});
it("does not write the keep key when it was never set (absent in raw and patch)", () => {
expect(thinkingOf(setAgentSettings({}, {}))).not.toHaveProperty("keep");
const next = setAgentSettings(
{ thinking: { enabled: true } },
{ thinking: { effort: "high" } }
);
expect(thinkingOf(next)).not.toHaveProperty("keep");
expect(thinkingOf(next).effort).toBe("high");
});
it("writes the key when an absent raw config's keep is explicitly toggled off", () => {
const next = setAgentSettings({}, { thinking: { keep: "off" } });
expect(thinkingOf(next).keep).toBe("off");
});
});
// ---------------------------------------------------------------------------
// loop_control — v2 default writes only max_attempts_per_step; legacyV1 opts
// dual-writes; read fallback from the v1 key is preserved
// ---------------------------------------------------------------------------
describe("loop_control — v1/v2 key handling", () => {
const raw = { loop_control: { max_attempts_per_step: 5, max_retries_per_step: 5 } };
it("default (v2): a save strips the legacy max_retries_per_step key", () => {
const next = setAgentSettings(raw, { loop_control: { reserved_context_size: 60000 } });
expect(loopOf(next).max_attempts_per_step).toBe(5);
expect(loopOf(next)).not.toHaveProperty("max_retries_per_step");
});
it("default (v2): a dual-write patch ends up with only the v2 key", () => {
const next = setAgentSettings(
raw,
{ loop_control: { max_attempts_per_step: 7, max_retries_per_step: 7 } }
);
expect(loopOf(next).max_attempts_per_step).toBe(7);
expect(loopOf(next)).not.toHaveProperty("max_retries_per_step");
});
it("legacyV1: both keys are written", () => {
const next = setAgentSettings(
raw,
{ loop_control: { max_attempts_per_step: 7, max_retries_per_step: 7 } },
{ legacyV1: true }
);
expect(loopOf(next).max_attempts_per_step).toBe(7);
expect(loopOf(next).max_retries_per_step).toBe(7);
});
it("read fallback keeps a max_retries_per_step-only config editable", () => {
const s = getAgentSettings({ loop_control: { max_retries_per_step: 4 } });
expect(s.loop_control?.max_attempts_per_step).toBe(4);
expect(s.loop_control?.max_retries_per_step).toBe(4);
});
});
// ---------------------------------------------------------------------------
// [permission] dangerous_command_guard (kimi-code 0.40.1) — absent key means
// upstream default ON; an explicit false must survive even with no rules
// ---------------------------------------------------------------------------
describe("permission.dangerous_command_guard", () => {
it("reads as undefined when the key is absent (default on)", () => {
expect(
getAgentSettings({}).permission?.dangerous_command_guard
).toBeUndefined();
expect(
getAgentSettings({ permission: { rules: [] } }).permission
?.dangerous_command_guard
).toBeUndefined();
});
it("reads an explicit true / false", () => {
expect(
getAgentSettings({ permission: { dangerous_command_guard: false } })
.permission?.dangerous_command_guard
).toBe(false);
expect(
getAgentSettings({ permission: { dangerous_command_guard: true } })
.permission?.dangerous_command_guard
).toBe(true);
});
it("writes guard=false even with no rules (section kept)", () => {
const next = setAgentSettings(
{},
{ permission: { rules: [], dangerous_command_guard: false } }
) as { permission?: Record<string, unknown> };
expect(next.permission).toEqual({ dangerous_command_guard: false });
});
it("writes guard together with rules", () => {
const rules = [{ decision: "allow" as const, pattern: "Read" }];
const next = setAgentSettings(
{},
{ permission: { rules, dangerous_command_guard: true } }
) as { permission?: Record<string, unknown> };
expect(next.permission).toEqual({
rules,
dangerous_command_guard: true,
});
});
it("a rules-only update carries the existing guard through", () => {
const raw = { permission: { dangerous_command_guard: false } };
const next = setAgentSettings(raw, {
permission: { rules: [{ decision: "deny" as const, pattern: "Bash" }] },
}) as { permission?: Record<string, unknown> };
expect(next.permission?.dangerous_command_guard).toBe(false);
expect(next.permission?.rules).toHaveLength(1);
});
it("omits an empty rules array; keeps an explicit guard on plain saves", () => {
const raw = { permission: { dangerous_command_guard: true } };
const off = setAgentSettings(raw, {
permission: { rules: [], dangerous_command_guard: false },
}) as { permission?: Record<string, unknown> };
expect(off.permission).toEqual({ dangerous_command_guard: false });
expect(off.permission).not.toHaveProperty("rules");
// An explicit true is materialized on plain saves (harmless, and it
// documents the state the UI toggle shows).
const on = setAgentSettings(raw, {}) as {
permission?: Record<string, unknown>;
};
expect(on.permission).toEqual({ dangerous_command_guard: true });
});
});
+69 -13
View File
@@ -49,20 +49,43 @@ export function getAgentSettings(rawOther: unknown): AgentSettings {
) {
loop.max_attempts_per_step = sectionLoop.max_retries_per_step;
}
const thinking = {
...DEFAULT_SETTINGS.thinking,
...getSection<AgentSettings["thinking"]>(rawOther, "thinking"),
};
// Upstream engines only accept string off values ("off"/"none"/"no"; see
// KEEP_OFF_VALUES) — a `false` from an old config fails the v2 validator
// and the v1 strict parse. Normalize every legacy off value to "off" for
// display; the serialization path (setAgentSettings) writes the string.
if (thinking.keep !== undefined && thinking.keep !== "all") {
thinking.keep = "off";
}
// The "max" effort tier was removed upstream (auto-migrates to "high");
// old configs still carrying it are shown as "high" (not rewritten on read).
if (thinking.effort === "max") {
thinking.effort = "high";
}
const sectionPermission = getSection<AgentSettings["permission"]>(
rawOther,
"permission"
);
return {
thinking: {
...DEFAULT_SETTINGS.thinking,
...getSection<AgentSettings["thinking"]>(rawOther, "thinking"),
},
thinking,
loop_control: loop,
background: {
...DEFAULT_SETTINGS.background,
...getSection<AgentSettings["background"]>(rawOther, "background"),
},
permission: {
rules:
getSection<AgentSettings["permission"]>(rawOther, "permission")?.rules ??
[],
rules: sectionPermission?.rules ?? [],
// `dangerous_command_guard` stays undefined unless the config carries
// an explicit boolean — upstream defaults it to ON (kimi-code 0.40.1),
// so an absent key means "on". The env var
// KIMI_CODE_DANGEROUS_COMMAND_GUARD (literal "true"/"false" only)
// outranks this config value at kimi-code runtime.
...(typeof sectionPermission?.dangerous_command_guard === "boolean"
? { dangerous_command_guard: sectionPermission.dangerous_command_guard }
: {}),
},
hooks: getSection<AgentSettings["hooks"]>(rawOther, "hooks") ?? [],
};
@@ -70,25 +93,58 @@ export function getAgentSettings(rawOther: unknown): AgentSettings {
export function setAgentSettings(
rawOther: unknown,
patch: Partial<AgentSettings>
patch: Partial<AgentSettings>,
opts?: { legacyV1?: boolean }
): unknown {
const root = { ...asRecord(rawOther) };
const current = getAgentSettings(rawOther);
// Explicit guard value wins over the carried-over one; undefined keeps the
// key absent (upstream default = on).
const guard =
patch.permission?.dangerous_command_guard ??
current.permission?.dangerous_command_guard;
const permission: NonNullable<AgentSettings["permission"]> = {
rules: patch.permission?.rules ?? current.permission?.rules ?? [],
...(typeof guard === "boolean" ? { dangerous_command_guard: guard } : {}),
};
const next: AgentSettings = {
thinking: { ...current.thinking, ...patch.thinking },
loop_control: { ...current.loop_control, ...patch.loop_control },
background: { ...current.background, ...patch.background },
permission: {
rules: patch.permission?.rules ?? current.permission?.rules ?? [],
},
permission,
hooks: patch.hooks ?? current.hooks ?? [],
};
// `keep` is only written when the source config explicitly carries it or the
// patch sets it — an absent key keeps the engine default ("all") instead of
// being materialized, so a plain save does not add the key.
const rawThinking = asRecord(getSection(rawOther, "thinking"));
const patchHasKeep = patch.thinking !== undefined && "keep" in patch.thinking;
if (!("keep" in rawThinking) && !patchHasKeep) {
delete next.thinking?.keep;
}
// The v2 engine (default) only reads max_attempts_per_step; the legacy v1
// key is stripped on save unless KIMI_CODE_LEGACY_FLAG=1 (v1 engine compat).
if (!opts?.legacyV1) {
delete next.loop_control?.max_retries_per_step;
}
if (next.thinking) root.thinking = next.thinking;
if (next.loop_control) root.loop_control = next.loop_control;
if (next.background) root.background = next.background;
if (next.permission?.rules && next.permission.rules.length > 0) {
root.permission = next.permission;
// Keep `[permission]` when it carries rules *or* an explicit
// dangerous_command_guard — dropping the section would silently lose a
// guard=false write (absent key = upstream default on). An empty rules
// array is omitted rather than written as `rules = []`.
const hasRules = !!permission.rules && permission.rules.length > 0;
const hasGuard = typeof permission.dangerous_command_guard === "boolean";
if (hasRules || hasGuard) {
root.permission = {
...(hasRules ? { rules: permission.rules } : {}),
...(hasGuard
? { dangerous_command_guard: permission.dangerous_command_guard }
: {}),
};
} else {
delete root.permission;
}
+18220 -4846
View File
File diff suppressed because it is too large. Load diff
+15157 -3826
View File
File diff suppressed because it is too large. Load diff
+102
View File
@@ -1,8 +1,12 @@
import { describe, expect, it } from "vitest";
import {
EXPERIMENTAL_FLAGS,
getExperimentalFlags,
getSecondaryModel,
getSubagentModelPool,
isExperimentalFlagSet,
removeSubagentPoolEntry,
setExperimentalFlag,
setSecondaryModelOnly,
setSubagentDefault,
setSubagentForce,
@@ -231,6 +235,31 @@ describe("pool mutations", () => {
expect(section(updated).default_model).toBe("kimi-k1");
});
it("upsertSubagentPoolEntry materializes the implicit default into a new table", () => {
// Implicit single-entry form (default_model set, no models table): adding a
// second alias must pull the default into the table, otherwise the result
// violates "default_model must be a pool key" (rule 3) and gets rejected.
const raw = rawWith({ default_model: "kimi-k1", force: false });
const added = upsertSubagentPoolEntry(raw, "kimi-k2", "");
expect(modelsOf(added)).toEqual({ "kimi-k1": "", "kimi-k2": "" });
expect(section(added).default_model).toBe("kimi-k1");
const pool = getSubagentModelPool(added);
expect(pool).toBeDefined();
expect(
validateSubagentPool(pool!, ["kimi-k1", "kimi-k2"]),
).toEqual([]);
});
it("upsertSubagentPoolEntry upgrades a legacy `model`-only section to a valid pool", () => {
const raw = rawWith({ model: "kimi-k1" });
const added = upsertSubagentPoolEntry(raw, "kimi-k2", "K2");
expect(modelsOf(added)).toEqual({ "kimi-k1": "", "kimi-k2": "K2" });
expect(section(added).default_model).toBe("kimi-k1");
expect(section(added).model).toBe("kimi-k1");
const pool = getSubagentModelPool(added);
expect(validateSubagentPool(pool!, ["kimi-k1", "kimi-k2"])).toEqual([]);
});
it("removeSubagentPoolEntry keeps the default when removing a non-default alias", () => {
const raw = rawWith({
default_model: "kimi-k1",
@@ -424,3 +453,76 @@ describe("validateSubagentPool", () => {
expect(errors).toContainEqual({ key: "forceExcludesModels" });
});
});
// ---------------------------------------------------------------------------
// [experimental] — flag registry (kimi-code 0.40.1) + write semantics
// ---------------------------------------------------------------------------
describe("experimental flag registry", () => {
it("mirrors the 0.40.1 v2 registry (10 flags incl. file_history)", () => {
expect(EXPERIMENTAL_FLAGS.map((f) => f.id)).toEqual([
"secondary-model",
"tool-select",
"persistence_minidb_readmodel",
"tower",
"subagent_fork",
"wait_for",
"auto_session_title",
"remote-control",
"search_worker",
"file_history",
]);
const fh = EXPERIMENTAL_FLAGS.find((f) => f.id === "file_history");
expect(fh?.envVar).toBe("KIMI_CODE_EXPERIMENTAL_FILE_HISTORY");
expect(fh?.defaultEnabled).toBeUndefined();
});
it("secondary-model is on by default since 0.40.1", () => {
expect(
EXPERIMENTAL_FLAGS.find((f) => f.id === "secondary-model")?.defaultEnabled
).toBe(true);
});
});
describe("setExperimentalFlag", () => {
const rawExp = (section: Record<string, unknown>) => ({
experimental: section,
});
it("enabling writes true; disabling a default-off flag deletes the key", () => {
const on = setExperimentalFlag({}, "tool-select", true) as {
experimental: Record<string, unknown>;
};
expect(on.experimental["tool-select"]).toBe(true);
const off = setExperimentalFlag(on, "tool-select", false) as Record<
string,
unknown
>;
expect(off).not.toHaveProperty("experimental"); // empty section dropped
});
it("disabling a default-on flag with explicitFalse writes a literal false", () => {
const next = setExperimentalFlag(
rawExp({ wait_for: true }),
"wait_for",
false,
{ explicitFalse: true }
) as { experimental: Record<string, unknown> };
expect(next.experimental.wait_for).toBe(false);
expect(isExperimentalFlagSet(next, "wait_for")).toBe(true);
expect(getExperimentalFlags(next).wait_for).toBe(false);
});
it("an explicit false coexists with other flags and keeps the section", () => {
const next = setExperimentalFlag(
rawExp({ "secondary-model": false }),
"tower",
true,
{ explicitFalse: true }
) as { experimental: Record<string, unknown> };
expect(next.experimental).toEqual({
"secondary-model": false,
tower: true,
});
});
});
+76 -8
View File
@@ -28,22 +28,57 @@ export interface ExperimentalFlagDef {
id: string;
/** Single-feature env var that can force the flag (locks the UI toggle). */
envVar: string;
/** Feature turned on by default upstream; an absent config key falls back
* to this, while an explicit `false` in `[experimental]` still wins. */
defaultEnabled?: boolean;
}
/** Known experimental flags (Kimi Code v1 + v2 registries, merged). */
/** Known experimental flags — mirrors the kimi-code v2 flag registry
* (the per-feature flag.ts files under packages/agent-core-v2/src:
* secondary-model, tool-select, persistence_minidb_readmodel, tower,
* subagent_fork, wait_for, auto_session_title, remote-control,
* search_worker, file_history). `acp-v2` was removed upstream and is
* dropped here. Keep the env-var list in sync with
* `get_experimental_env_status` in src-tauri/src/commands.rs. */
export const EXPERIMENTAL_FLAGS: ExperimentalFlagDef[] = [
{ id: "secondary-model", envVar: "KIMI_CODE_EXPERIMENTAL_SECONDARY_MODEL" },
{
id: "secondary-model",
envVar: "KIMI_CODE_EXPERIMENTAL_SECONDARY_MODEL",
defaultEnabled: true, // on by default since kimi-code 0.40.1
},
{ id: "tool-select", envVar: "KIMI_CODE_EXPERIMENTAL_TOOL_SELECT" },
{ id: "acp-v2", envVar: "KIMI_CODE_EXPERIMENTAL_ACP_V2" },
{
id: "persistence_minidb_readmodel",
envVar: "KIMI_CODE_EXPERIMENTAL_PERSISTENCE_MINIDB_READMODEL",
defaultEnabled: true,
},
{ id: "tower", envVar: "KIMI_CODE_EXPERIMENTAL_TOWER" },
{ id: "subagent_fork", envVar: "KIMI_CODE_EXPERIMENTAL_SUBAGENT_FORK" },
{
id: "wait_for",
envVar: "KIMI_CODE_EXPERIMENTAL_WAIT_FOR",
defaultEnabled: true,
},
{
id: "auto_session_title",
envVar: "KIMI_CODE_EXPERIMENTAL_AUTO_SESSION_TITLE",
},
{ id: "remote-control", envVar: "KIMI_CODE_EXPERIMENTAL_REMOTE_CONTROL" },
{
id: "search_worker",
envVar: "KIMI_CODE_EXPERIMENTAL_SEARCH_WORKER",
defaultEnabled: true,
},
{ id: "file_history", envVar: "KIMI_CODE_EXPERIMENTAL_FILE_HISTORY" },
];
export const EXPERIMENTAL_MASTER_ENV = "KIMI_CODE_EXPERIMENTAL_FLAG";
/** Whether the master env var is set to a truthy value (locks every flag on). */
/** Whether the master env var is set to a truthy value. Since kimi-code
* 0.40.1 it only force-ONs flags that have *no* explicit `[experimental]`
* entry (an explicit config value — true or false — outranks it, and the
* master env can never force a flag off). It locks no UI toggles; only a
* flag's own single-feature env var does. */
export function isMasterEnvOn(env: ExperimentalEnvStatus | null): boolean {
return isTruthyEnv(env?.[EXPERIMENTAL_MASTER_ENV]);
}
@@ -77,16 +112,33 @@ export function getExperimentalFlags(rawOther: unknown): Record<string, boolean>
return out;
}
/** Set one flag in `[experimental]`. Removing all flags drops the section. */
/** Whether a flag is explicitly written in `[experimental]` (true *or* false).
* An absent flag falls back to the upstream default (`defaultEnabled`). */
export function isExperimentalFlagSet(rawOther: unknown, id: string): boolean {
return Object.prototype.hasOwnProperty.call(
asRecord(asRecord(rawOther)["experimental"]),
id
);
}
/** Set one flag in `[experimental]`. Removing all flags drops the section.
* Pass `explicitFalse` when deleting the key would NOT express "off" —
* i.e. the flag is on by upstream default (`defaultEnabled`) or the master
* env force-ons undefined flags — and write a literal `false` instead,
* which outranks both under the kimi-code 0.40.1 priority
* (single env > explicit config > master env > default). */
export function setExperimentalFlag(
rawOther: unknown,
id: string,
enabled: boolean
enabled: boolean,
opts?: { explicitFalse?: boolean }
): unknown {
const root = { ...asRecord(rawOther) };
const flags = { ...getExperimentalFlags(rawOther) };
if (enabled) {
flags[id] = true;
} else if (opts?.explicitFalse) {
flags[id] = false;
} else {
delete flags[id];
}
@@ -246,8 +298,11 @@ export function setSubagentModelPool(
return root;
}
/** Add or update one alias in the pool `models` table. The rest of the
* section (default, force, unknown fields) is preserved untouched. */
/** Add or update one alias in the pool `models` table. When the section is
* the implicit single-entry form (a `default_model`/`model` but no table),
* the effective default is materialized into the table first — otherwise the
* new table would fail the engine rule "default_model must be a pool key".
* The rest of the section (force, unknown fields) is preserved untouched. */
export function upsertSubagentPoolEntry(
rawOther: unknown,
alias: string,
@@ -259,8 +314,21 @@ export function upsertSubagentPoolEntry(
for (const [k, v] of Object.entries(section)) next[k] = v;
const models: Record<string, unknown> = {};
for (const [k, v] of Object.entries(asRecord(next.models))) models[k] = v;
const effectiveDefault =
typeof next.default_model === "string" && next.default_model !== ""
? next.default_model
: typeof next.model === "string" && next.model !== ""
? next.model
: undefined;
if (effectiveDefault !== undefined && !(effectiveDefault in models)) {
models[effectiveDefault] = "";
}
models[alias] = description;
next.models = models;
if (effectiveDefault !== undefined) {
next.default_model = effectiveDefault;
next.model = effectiveDefault;
}
root.secondary_model = next;
return root;
}
+31 -3
View File
@@ -6,7 +6,9 @@ export type ProviderType =
| "openai"
| "openai_responses"
| "google-genai"
| "vertexai";
| "vertexai"
/** Any other string the CLI writes — preserved verbatim on round-trip. */
| (string & {});
export interface Provider {
name: string;
@@ -62,6 +64,12 @@ export interface Config {
providers: Record<string, Provider>;
models: Record<string, Model>;
raw_other?: unknown;
/**
* Top-level section keys captured at import time by the Rust side.
* Export drops only baseline keys absent from raw_other (sections the
* user removed in the UI); CLI-added sections are preserved.
*/
imported_section_keys?: string[];
}
/**
@@ -92,7 +100,18 @@ export interface DiscoveredModel {
export interface ThinkingConfig {
enabled?: boolean;
/**
* Effort tier. `max` is read-compatible only — upstream removed the tier
* (old configs auto-migrate to `high`); the UI normalizes it and the
* serialization path never writes it.
*/
effort?: "low" | "medium" | "high" | "max";
/**
* Keep thinking content. The legacy off values (`false`, `0`, "no", "none",
* `null`) are read-compatible — old configs may carry them; the UI
* normalizes them to `"off"` and the serialization path never emits a
* boolean (upstream engines only accept string off values).
*/
keep?: "all" | false | 0 | "no" | "off" | "none" | null;
}
@@ -101,7 +120,8 @@ export interface LoopControlConfig {
max_attempts_per_step?: number;
/** v2 engine key (kimi-code 0.33+): `max_steps_per_run` was renamed. */
max_steps_per_turn?: number;
/** Legacy v1 key — written in sync so KIMI_CODE_LEGACY_FLAG=1 still works. */
/** Legacy v1 key — read fallback only; written/kept only when
* KIMI_CODE_LEGACY_FLAG=1 (v1 engine compat). v2 saves strip it. */
max_retries_per_step?: number;
reserved_context_size?: number;
}
@@ -129,7 +149,15 @@ export interface AgentSettings {
thinking?: ThinkingConfig;
loop_control?: LoopControlConfig;
background?: BackgroundConfig;
permission?: { rules?: PermissionRule[] };
permission?: {
rules?: PermissionRule[];
/** kimi-code 0.40.1 `[permission]` key. Default true when the key is
* absent: Auto mode refuses dangerous commands (rm -rf, shutdown,
* dd of=, …) and other modes always prompt; false restores the
* previous behavior. Env KIMI_CODE_DANGEROUS_COMMAND_GUARD (literal
* "true"/"false" only) outranks this config. */
dangerous_command_guard?: boolean;
};
hooks?: Hook[];
}